2023-07-25 | DOF 5697449Added · Updated
This document establishes Annex 1 to the Third Resolution of Modifications to the General Rules for Foreign Trade for 2023, detailing the specific formats, models, declarations, and applications required for foreign trade operations in Mexico. It mandates the use of standardized profiles for various entities, including companies, customs brokers, and transporters, submitted via the AGACE Digital Window or in writing. The text specifies the content and submission instructions for the Company Profile (E3), which requires businesses to demonstrate compliance with minimum security standards, risk analysis procedures, and internal audit processes to obtain or maintain certification under the Authorized Economic Operator scheme.
6 OFFICIAL GAZETTE Thursday, August 3, 2023
ANNEX 1 to the Third Resolution of Modifications to the General Rules for Foreign Trade for 2023, published on July 25, 2023.
A seal with the National Coat of Arms appears at the margin, which reads: United Mexican States.- TREASURY.- Ministry of Finance and Public Credit.- Tax Administration Service.
FIRST MODIFICATION TO ANNEX 1 OF THE GENERAL RULES FOR FOREIGN TRADE FOR 2023
Formats and Models for Foreign Trade
Content I. ... II. Foreign Trade Formats. A. to C. ... D. Declarations. E. Formats. F. Applications.
Indicative References
| Format Name | Authority before which it is presented | Submission Method |
|---|---|---|
| A. to C. ... | ... | ... |
D. Declarations
| Declaration Name | Authority before which it is presented | Submission Method |
|---|---|---|
| D1. ... | ... | ... |
| D2. Customs declaration for passengers coming from abroad (Spanish and English). | Customs | Free writing |
| D3. Declaration of money leaving with passengers (Spanish and English). | Customs | Free writing |
| D4. to D9. ... | ... | ... |
E. Formats
| Format Name | Authority before which it is presented | Submission Method |
|---|---|---|
| E1. and E2. ... | ... | ... |
| E3. Company Profile. | AGACE | Digital Window |
| E4. Customs Broker Profile. | AGACE | Digital Window |
| E5. Land Auto Transporter Profile. | AGACE | Digital Window |
| E6. Courier and Parcel Service Profile. | AGACE | Digital Window |
Thursday, August 3, 2023 OFFICIAL GAZETTE 7
E7. Fiscalized Premises Profile. | AGACE | Digital Window E8. Strategic Fiscalized Premises Profile. | AGACE | Digital Window E9. Railway Transporter Profile. | AGACE | Digital Window E10. Industrial Parks Profile. | AGACE | Digital Window E11. General Warehouse Profile. | AGACE | Digital Window E12. to E14. ... | ... | ...
F. Applications
| Application Name | Authority before which it is presented | Submission Method |
|---|---|---|
| F1. and F2. ... | ... | ... |
| F3. Application for Registration in the Company Certification Scheme. | AGACE | Free writing / Digital Window |
| F3.1 and F3.2 ... | ... | ... |
| F3.3 Procedure guide to obtain Registration in the Company Certification Scheme in the Authorized Economic Operator modality under the headings of Import and/or Export; Holding Company; Aircraft; SECIIT; Textile; Strategic Fiscalized Premises and Logistics Outsourcing. | AGACE | Free writing |
| F3.4 Procedure guide to obtain Registration in the Company Certification Scheme, Certified Commercial Partner modality, headings: land auto-transporter, customs broker, railway transport, industrial parks, fiscalized premises, and courier and parcel service. | AGACE | Digital Window |
| F4. and F5. ... | ... | ... |
III. ...
Indicative References
| Model Name | Authority before which it is presented | Submission Method |
|---|---|---|
| M1.1. to M1.11. ... | ... | ... |
| I. ... | ||
| II. Foreign Trade Formats: | ||
| ... |
D2.
12 OFFICIAL GAZETTE Thursday, August 3, 2023
D3.
Thursday, August 3, 2023 OFFICIAL GAZETTE 13
E3. Company Profile.
Receipt Acknowledgment First Time: Renewal: Addition: Modification: The data provided will replace the data provided when you requested your authorization.
General Information. The objective of this Profile is to ensure that companies implement security practices and processes that secure their supply chain to mitigate the risk of contamination of their merchandise with illicit products.
Companies interested in obtaining their inscription in the Registration in the Company Certification Scheme in the Authorized Economic Operator modality under the headings of Importer and/or Exporter, Holding Company, Aircraft, SECIIT, Textile and Logistics Outsourcing referred to in rule 7.1.4., must demonstrate that they have documented and verifiable processes required in this document according to the model or business design they have established based on risk management, seeking during the implementation of minimum security standards the application of an analysis culture that supports preventive and reactive decision-making against threats and/or risk circumstances in accordance with the values, mission, vision, codes of ethics and conduct of the company itself.
Filling Instructions:
You must fill out one Profile for each of the facilities that operate under the same RFC (Taxpayer Registration Code), where they carry out manufacturing processes of foreign trade products and, if applicable, those related facilities such as: industrial and/or manufacturing plants, warehouses, distribution centers, consolidation, among others. This information must match what is stated in your Application for Registration in the Company Certification Scheme.
Detail how the company complies with or exceeds what is established in each of the subsections as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Description of the standard 1.1 Sub-standard. Description of the sub-standard Response. Explanatory Notes. Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards, therefore you must attach the procedures in Spanish that, if applicable, are required, or provide a detailed explanation of what is requested in the Response field. The section regarding Explanatory Notes is a guide regarding the points that must be included in the Response, for each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once this Company Profile is answered, you must attach it to the Application for Registration in the Company Certification Scheme referred to in the first paragraph of rule 7.1.4., fraction IV. For the purpose of verifying what is stated in the previous paragraph, the SAT through the AGACE may carry out an inspection of the facility indicated here, with the exclusive purpose of verifying what is stated in this document.
Any incomplete Company Profile will not be processed.
Any question related to the Application for Registration in the Company Certification Scheme and the Company Profile, direct it to the contacts that appear on the SAT Portal.
In the event of being authorized with the Registration in the Company Certification Scheme, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and derived from these changes or modifications are required in the information stated and provided in this Company Profile to the authority, in accordance with what is established in rule 7.2.1., third paragraph, fractions III and IV.
When derived from the inspection visit, non-compliance related to minimum security standards results, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the non-compliances indicated.
Installation Data. A Company Profile must be filled out for each of the facilities that belong to and operate under the same RFC and that carry out manufacturing processes of foreign trade products and, if applicable, those related facilities such as: industrial and/or manufacturing plants, warehouses, distribution centers, consolidation, etc.
Installation Information. Company Profile Number: RFC Name and/or Business Name: Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of the plant (years of operation): Predominant activity of the plant: Products that it manufactures or handles in this plant: (As applicable) No. of average monthly shipments (EXP): (By transport means) No. of average monthly shipments (IMP): (By transport means) No. of total employees of this installation: Installation surface (m2):
Certifications in security programs: (Indicate if this installation has a certification from any of the following programs) CTPAT Yes No Level: Pre-Applicant: Applicant: Certified: Certified/Validated: CTPAT Account number (8 digits): Manufacturer Identification Code (MID): Date of last visit to this installation: Authorized Economic Operator from other countries (AEO): Yes No Program: Registration: Other supply chain security programs: Yes No Program: Registration: Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The company must establish measures to identify, analyze and mitigate security risks within the supply chain and its facilities. For the above, it must develop a written process to determine risks based on its organization's model (example: location of facilities, type of merchandise and country of origin, volume, clients, suppliers, routes, personnel hiring, classification and handling of documents, Information Technology, potential threats, etc.), which allows it to implement and maintain appropriate security measures. Based on the above, the company must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be updated at least once a year, so that it allows permanently identifying other risks or threats that are considered in its operation and in the supply chain, due to the result of some security incident or when they originate from changes in the company's initial conditions, as well as to identify that the policies, procedures and other control and security mechanisms are being complied with. It is important to note that the company's Security Committee must participate in the elaboration and updating of the risk analysis, as well as in the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate what the sources of information used are to calibrate risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the facilities of your company, which must include at least the following points: a) Periodicity with which it reviews and/or updates the risk analysis. b) Aspects and/or areas of the company that are incorporated into the risk analysis. c) Methodology or techniques used to carry out the risk analysis. d) Those responsible for reviewing and/or updating the risk analysis of the company. Likewise, the documented procedure to identify risks in the supply chain and its facilities, must contemplate the risk appreciation and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Identification of risks in its supply chain and its facilities. c) Risk analysis (causes, consequences, probabilities and existing controls to determine the level of risk as high, medium and low). d) Risk evaluation (decision making to determine the risks to treat and priority for implementing the treatment). e) Risk treatment (application of alternatives to change the probability of risks occurring). f) Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use the administration, management and risk evaluation techniques according to international standards ISO 31000, ISO 31010 and ISO 28000 that, according to your business model, you must implement.
1.2 Security Policies. The company must have a policy oriented to prevent, secure and recognize threats in the security of the supply chain and the company's installations, such as drug trafficking, money laundering, arms trafficking, human trafficking, prohibited merchandise and acts of terrorism. To promote a security culture, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The senior officials or executives of the company who must endorse and sign the security policy can be the company president, the chief executive officer, the general manager or personnel with a homologous position with decision-making authority.
Response: Explanatory Notes: State the security policy oriented to prevent, secure and recognize threats in the supply chain and company installations, indicate who is responsible for its review, signature and dissemination to employees, as well as the periodicity with which its update is carried out. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the company's initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out periodic audits, which allow evaluating all processes in terms of security in the supply chain in a more critical and profound way, as well as guaranteeing that its employees follow the company's security procedures. Audits must be carried out by the company's Security Committee, establish a documented procedure, as well as a program or calendar for their realization. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review and execution of minimum security standards, their focus must be adjusted to the size of the organization, risk level, business model and variations between installations. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex, however, the formats and records used for the application of such reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the follow-up and closure of preventive, corrective and improvement actions identified. The senior management of the organization must review the results of the audits, and undertake the corrective or preventive actions required. The audit process must guarantee that the necessary information is collected to allow management to make this evaluation. The review must be documented, in addition to which the company's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit focused on security in the supply chain, ensure you include the following points: a) Indicate how the company carries out the programming or calendarization to carry out an internal audit in terms of security in the supply chain. b) Indicate who participates in them, and the records that are effectuated from them, as well as the periodicity with which they are carried out. c) Indicate how the company's management verifies the result of the audits in terms of security, how it carries out and/or implements preventive, corrective and improvement actions, in addition to the follow-up and closure of the same. d) The formats used during internal audits must be properly filled out, and through them, evidence that the procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan, this plan must address crisis management, security recovery plans and the resumption of work to ensure business continuity in the event of a situation that affects the normal development of the activities and foreign trade operations of the company in its supply chain. A crisis or contingency may include the interruption of the transmission and exchange of commercial data due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, (a customs closure, a bomb threat, the detection of suspicious packages, the cut of electrical power, the theft and/or damage of merchandise, threats or extortion, blockades or road closures, among others). Such plans must be communicated to personnel through periodic training, as well as carrying out tests, practical exercises and annual simulations of the contingency and emergency plans to verify their effectiveness, from which it must maintain a duly filled out and signed record (for example: result reports, minutes or reports, which must be backed up by video recordings, photographs, etc., that demonstrate their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in case of an emergency or security situation, that affects the normal development of the company's foreign trade activities. This procedure must include, in an enumerative but not limiting manner, the following: a) What situations it contemplates, describing the plan of action and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. b) What mechanisms it uses to disseminate and ensure that these plans are effective. c) Contemplate the programming and carrying out of tests, practical exercises and annual simulations and how they are documented (for example: result reports, minutes or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution).
2.1 Facilities. Facilities must be constructed with materials capable of resisting unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of structures, and in case any irregularity is detected, the corresponding repair must be made, for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution. Likewise, territorial limits, as well as various accesses, internal routes, and the location of buildings, must be fully identified. Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example: metal structure and sheet walls, brick walls, concrete, cyclone mesh, among others), and indicate how the review and maintenance of structural integrity is carried out. Indicate the personnel or area responsible for carrying out inspection, maintenance, and damage repair tasks for the facilities. Attach a distribution or architectural plan of the complex, where the limits of the installations, access routes, emergency exits, location of buildings, critical areas, parking lots, and boundaries can be identified.
2.2 Accesses at doors and booths. The entrance or exit doors for vehicles and/or personnel must be attended, controlled, watched, and/or supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the installations, as well as the operating hours of each, and indicate how they are monitored (if there is assigned personnel, indicate the quantity). Detail if there are blocked and/or permanently closed doors and/or accesses. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Walls. Perimeter walls and/or peripheral barriers must be installed to secure the parameters of the company's facilities, based on a risk analysis. Fences, interior barriers, or a mechanism to identify and segregate international cargo, as well as high-value and dangerous cargo, must be used. These must be inspected regularly and keep a record of the review with the aim of ensuring their integrity and identifying damage, which must be repaired as soon as possible by the personnel designated for these tasks. Storage areas, high-value, dangerous, and/or restricted-access areas must be clearly identified and monitored to prevent unauthorized entries. Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls that the company has, make sure to include the following points: a) Specify which areas are segregated. b) Point out their characteristics (material, dimensions, etc.). c) In case of not having walls, justify the reason in detail. d) Frequency with which the integrity of the perimeter walls is verified and the records that are kept with the aim of ensuring their integrity and identifying damage, which must be repaired as soon as possible. e) Indicate the personnel or area responsible for carrying out inspection and damage repair tasks. Describe how the cargo destined for foreign countries, dangerous material, and high-value material is segregated; make sure to include the following points: a) Indicate how you separate national merchandise and foreign trade merchandise, and if it is additionally identified (for example: different packaging, labels, packing, among others). b) Identify and point out restricted-access areas (dangerous merchandise, high value, confidential, etc.). The procedure for inspecting perimeter walls could include: a) Responsible personnel to carry out the process. b) How and how often inspections of fences, perimeter walls, and/or peripheral walls and buildings are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that repairs and/or modifications comply with technical specifications and necessary security requirements.
2.4 Parking Lots. Access to the facility parking lots must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers, contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas. Response: Explanatory Notes: Describe the procedure for controlling and monitoring parking lots, make sure to include the following points: a) Those responsible for controlling and monitoring access to parking lots. b) Identification of parking lots (specify if the visitor and employee parking is separated from the storage and merchandise handling areas). c) How vehicle entry and exit to the facilities is controlled. Indicate the records made for parking control, existing control mechanisms (for example: badges, card readers, lanyards, etc.), how they are assigned, and the responsible area for doing so. d) Policies or mechanisms to not allow private vehicles into the merchandise storage and handling areas.
2.5 Key and Lock Device Control. Windows, doors, as well as interior and exterior fences, according to their risk analysis, must be secured with locking devices. The company must have a documented procedure for the handling and control of keys and/or locking devices for interior areas considered critical. Likewise, they must keep a record and establish signed responsibility letters by persons who have keys or authorized access according to their level of responsibility and work within their work area. Response: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have closing or security mechanisms. Attach the documented procedure for the handling and control of keys and/or locking devices, make sure it includes the following points: a) Those responsible for administering and controlling key security. b) Format and/or control record for key lending. c) Treatment for loss or non-return of keys. d) Point out if there are areas where access is granted with electronic devices and/or some other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of people, material, and/or equipment located therein, including the following areas: entrances and exits, handling, loading, unloading, and storage areas for merchandise, perimeter and/or peripheral walls, interior fences, and parking areas, and must have an emergency and/or backup system in sensitive areas. Response: Explanatory Notes: Describe the procedure for operating and maintaining the lighting system, make sure to include the following points: a) Point out which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant or some other mechanism to supply electricity in case of any contingency). b) How do you ensure that the lighting system is appropriate in each of the company's areas, so that it allows clear identification of the personnel, material, and/or equipment located there. c) Person responsible for controlling and maintaining lighting systems. d) Maintenance and revision program (in case it coincides with another process, indicate it). The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting.
2.7 Communication Devices. The company must have communication devices and/or systems with the aim of contacting security personnel and/or authorities immediately in case of an emergency and security situation. Additionally, a backup system must be available and its proper functioning verified periodically. Response: Explanatory Notes: Describe the procedure that personnel must perform to contact the company's security personnel or, in their case, the corresponding authority in case of any security incident. Indicate if operational and administrative personnel have or dispose of devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or whoever corresponds (these must be accessible to users to have a prompt reaction). Indicate what type of communication devices the company's security personnel uses (landline phones, cell phones, radios, alarm system, etc.). Describe the procedure for controlling and maintaining communication devices, make sure to include the following points: a) Policies for assigning mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate if you have backup communication devices, in case the permanent system fails, and, if applicable, describe them briefly. The procedure may include: a) Person responsible for the good functioning and maintenance of communication devices. b) Verification and maintenance record of the devices. c) Method of assigning communication devices.
2.8 Alarm Systems, Closed-Circuit Television, and Video Surveillance. Alarm systems, closed-circuit television, video surveillance, and security technologies must be used to watch, notify, or deter unauthorized access and prohibited activities in the facilities and other considered sensitive areas, notify the corresponding area, and also be used as evidence tools in investigations derived from any security incident. These security systems and technologies must be placed according to a prior risk analysis, in such a way that areas involving the handling, loading, unloading, and storage of merchandise, raw materials, and packaging materials are kept under watch and monitored, security inspections of cargo vehicles, as well as the access of personnel, visitors, suppliers, passenger and cargo vehicles, and other considered sensitive areas. These systems must allow clear identification of the area or environment being watched, be recording permanently, and keep a backup of recordings for at least one month, considering that, in case their logistics processes exceed this period, the backup maintenance period must be increased, with the aim of having the necessary elements to assign corresponding responsibilities in case of a security incident. Alarm systems, closed-circuit television, video surveillance, and security technologies must have a documented operation procedure that includes supervision of the good condition of the equipment, verification of the correct position of cameras, indicating the frequency with which backups of recordings must be made, as well as those responsible for their operation. Such system and all security technology infrastructure must have restricted access. Response: Explanatory Notes: Mention the documented procedure indicating the functioning of the external alarm central or sensors, and if applicable, describe the following points: a) Indicate if all doors and windows have alarm sensors, as well as areas where motion sensors are available. b) Procedure to follow in case an alarm is activated. Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), make sure to include the following points: a) Indicate the number of security cameras of the alarm and closed-circuit television and video surveillance systems installed, and their location by area (Detail if it covers loading and unloading zones, including entry and exit points of the facilities, to cover the movement of vehicles and individuals, and where the inspection indicated in sub-standard 7.2 takes place). Attach a layout or map of the distribution of security cameras. b) Point out the location of alarm systems, closed-circuit television, video surveillance, and security technologies, where monitors are located, who reviews them, as well as operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Periodic and random reviews of recordings must be carried out. Indicate how they review them (randomly, every week, special events, restricted areas, etc.), who is the designated personnel, and how management gets involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept (must be at least one month). e) Alarm systems, closed-circuit television, video surveillance, and security technologies must have an alternative energy source that allows them to continue functioning in case of unexpected loss of direct power. For this reason, indicate if alarm systems, closed-circuit television, video surveillance, and security technologies are backed up by an electrical power plant or some other mechanism to supply electricity, guaranteeing their functioning. These systems should have an alarm/notification function, indicating a failure condition in functioning and/or recording, point out if your systems have this function. f) Indicate if, in addition to alarm systems, closed-circuit television, and video surveillance, you use any other type of technology to strengthen the security measures already in place. g) Describe the procedure implemented to regularly test and inspect alarm systems, closed-circuit television, video surveillance, and security technologies and ensure their good functioning. The results of inspections and functioning tests must be documented, as well as necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. h) Indicate if the alarm provider and alarm, closed-circuit television, and video surveillance systems have access to security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security Personnel. The company must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and merchandise during its transport, handling, and safeguarding within the company, as well as for controlling the entry and exit of all persons to the property. Security personnel must have a documented procedure to carry out their functions and have full knowledge of mechanisms and procedures in emergency situations, detection of unauthorized persons, or any security incident in the facility. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution. Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel and make sure to include the following points: a) Indicate the number of security personnel working in the company. b) Point out the positions and/or functions of the personnel and operating hours. c) In case of hiring an external service, provide general data of the company (RFC, Legal Name, Address), and specify the number of employed personnel, operational details, records, and reports they use to perform their functions. d) In case of having armed personnel, describe the procedure for the control and safeguarding of weapons.
3.2 Employee Identification. There must be an employee identification system for access to the facilities. Employees should only have access to those areas they need to perform their functions. Management or the company's security personnel must adequately control the delivery and return of badges, ID cards, and/or employee identification credentials. Procedures for the delivery, return, and change of access devices (for example, keys, badges, and/or credentials, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Describe the procedure for employee identification and make sure to include the following points: a) Identification mechanisms (badge and/or photo credential, access control, biometrics, proximity cards, etc.). b) Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable). c) Indicate how contracted personnel by a business partner, working within the facilities (contractors, subcontractors, in-house services, sub-maquila, etc.) is identified. Describe how the company delivers, changes, and withdraws employee identifications and access controls and make sure to include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for the control of identifications.
3.3 Visitor and Supplier Identification. To have access to the facilities, visitors and suppliers must present official identification with a photograph for documentation upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification, must be accompanied by company personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented. Response: Explanatory Notes: Describe the procedure for controlling access of visitors and suppliers, make sure to include the following points: a) Point out what records are kept (personal forms for each visit, logbooks, among others). b) The visitor and supplier record must include the following:
Date of the visit.
Name of the visitor.
Photo identification number (official documents such as: driver's license, passport, INE, etc.).
Time of entry and exit.
In the case of vehicular access, the format must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.). c) Indicate who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry.
3.4 Procedure for identification and removal of unauthorized persons or vehicles. The company must have documented procedures that specify how to identify, confront, or report unauthorized or unidentified persons and/or vehicles; this procedure must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or unidentified persons and/or vehicles. The procedure must include: a) Responsible personnel. b) Designate a person or area responsible for being informed of security incidents. c) Instructions on how to confront and address unidentified personnel. d) Indicate in which cases the corresponding authorities must be reported to. e) How security incidents and measures taken in each case are recorded.
3.5 Courier and package deliveries. Courier and package deliveries intended for company personnel must be examined upon arrival and departure, before being distributed to the corresponding areas and destinations. Likewise, the company must have a documented procedure for the receipt and review of courier and package deliveries, which must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and package deliveries and ensure you include the following: a) Personnel in charge of carrying out the procedure. b) Indicate how the personnel or supplier of the courier and package delivery service is identified (indicate if an additional procedure to the supplier access procedure is required). c) Indicate how the review of the courier and/or packages is carried out, what mechanism is used, the records kept, and in case, the incidents detected. d) Describe the characteristics or elements to determine which courier and/or package deliveries are suspicious. e) Indicate what action is taken in the event of detecting suspicious courier and/or packages.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses, as well as investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorist financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the company must avoid contracting them and, if applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions. Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new commercial partners and monitoring of partners already working with them; this includes any type of supplier that has a commercial relationship with the company and, if applicable, with the service outsourcing company, in its supply chain (it is in the next sub-standard where it is requested to differentiate those at risk in its supply chain), ensure you include the following points: a) What information is required from its commercial partner. b) What aspects are reviewed and investigated. c) Indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to indicating all those alerts to determine that a commercial partner is not reliable and thus, conduct a deeper investigation and evaluate whether to work with them.
d) Indicate if it maintains a physical or electronic file of each of its commercial partners, as well as the information it must contain. e) Indicate how the services of its commercial partner are evaluated and what points are reviewed. The file must include at a minimum the following: a) Company data (name, RFC, activity, etc.). b) Legal representative data. c) Proof of address. d) Commercial references (if applicable). e) Contracts, agreements, and/or confidentiality agreements and security policies. f) If applicable, certificate or certification number in the security programs to which it belongs.
4.2 Security requirements. The company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in its supply chain, whether as suppliers of materials for the manufacture, packaging, or packing of merchandise subject to foreign trade, as well as from transport service providers (long-haul, cross-border or transfer, Ex Works, subcontracted, etc.) for the transport and/or distribution of merchandise subject to foreign trade, customs brokers, logistics outsourcing providers (3PL, third-party logistics or 4PL, main logistics provider), warehouses, sub-maquiladora companies, manufacturers, sellers, suppliers of national and foreign parts and raw materials, direct and indirect, suppliers of cleaning services, private security, personnel hiring, high-security seal suppliers, collection and recycling, suppliers of systems and Information Technologies, among others. The requirements must be based on the Company Profile established by the AGACE, or in case it exists, the specific Profile for each actor in the supply chain that corresponds to it. The company must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in the Company Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation supporting compliance with the requirements established in the Authorized Economic Operator Program. In the case of the Service Outsourcing Company that has commercial partners contracted to provide customs management, storage, handling, transport, and/or distribution of merchandise subject to foreign trade services on its behalf, they must be registered in the Registry in the Certification of Companies Scheme, in the modalities of Authorized Economic Operator and Certified Commercial Partner in any of its areas or have the CTPAT Program, granted by the CBP. Likewise, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of the company's commercial partners that provide their services within the facilities, they must be obliged to comply with these supply chain security requirements. Response: Explanatory Notes: Describe the procedure that indicates how it carries out the identification of commercial partners that require compliance with minimum security standards. Ensure you include the following points: a) A register of commercial partners that must comply with security requirements, and mention what type of providers these are (carriers for the transport and/or distribution of merchandise subject to foreign trade, warehouses, custody service, private security company, customs brokers, etc.).
b) Indicate in what documentary form (agreements, accords, contractual clauses, and/or addenda) it ensures that its commercial partners comply with security requirements. c) Indicate if there are agreements, accords, contractual clauses, and/or addenda regarding the implementation of security measures with its service providers inside its company, such as: private security, cafeteria, gardening, cleaning and maintenance services, Information Technology providers, etc. d) Indicate if it has commercial partners to whom membership in a supply chain security program is required (for example: CTPAT or any other World Customs Organization Authorized Economic Operator Program), as well as the information and documentation requested of them.
4.3 Commercial partner reviews. The company, through the Security Committee, must carry out periodic security evaluations (as well as those derived from risk situations) of the processes and facilities of business associates based on a risk analysis to guarantee that they have the minimum security standards required by the company based on the Authorized Economic Operator Program, keep records of them, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the company must communicate them to its partner and/or supplier and provide a justified period to address the observations or areas for opportunity identified or, otherwise, have the necessary measures to sanction it. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program; that is why, in addition to a documented procedure, there must be a program or calendar for the execution of said security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and facilities of its commercial partners function correctly, it puts its supply chain at risk. Response: Explanatory Notes: Describe the procedure to carry out evaluations for the verification of security requirements (processes and facilities) of its commercial partners; ensure you include the following points: a) Periodicity with which it visits the commercial partner (these must be at least once a year and derived from risk situations). b) Program or calendar for the execution of security reviews. c) Record or report of the verification, and in case, the corresponding follow-up. d) The verification format(s) must be duly filled out, placing the date, name, and position of those participating in the review, signatures, etc.
e) Indicate what action measures are taken in case commercial partners do not comply with the established security requirements. In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the periodicity with which its status is reviewed, how it is recorded, and the actions taken in case it is detected that it is suspended and/or cancelled, according to what is established in its procedure. The procedure must include: a) Periodicity of visits; b) Points of review in security matters; c) Report preparation; d) Feedback and agreements with the commercial partner; e) Follow-up to agreements; f) Measures in case of detection of non-compliance with requirements; g) Record of evaluations; h) Area or person responsible for carrying out this procedure.
5.1 Process mapping. There must be a map that shows step by step the logistical process of the flow of merchandise and the required documentation through its international supply chain. The company must take into account and include within its mapping all parties involved in its supply chain, containing those that handle import and export documentation, such as customs brokers, others that may not handle the cargo directly but may have operational control such as carriers (long-haul, cross-border or transfer, Ex Works, subcontracted, etc.), logistics outsourcing providers (3PL/4PL), storage, sub-maquiladora, national and foreign suppliers, direct and indirect, etc. If within its supply chain any part of the transport is subcontracted, it is indispensable that it be considered within its risk analysis and process mapping, since the more direct and indirect suppliers, the greater the risk involved. Response: Explanatory Notes: Attach the document where the mapping of processes through which its import and export merchandise passes is illustrated and described, from the point of origin to the destination, with the purpose of having correctly identified each of the steps involving the manufacture and delivery of the final product. The process mapping must include, the names (RFC and corporate name) of the companies that provide services in its logistics chain.
This mapping must contain at least the following aspects: a) Origin of:
5.2 Warehouses and distribution centers. In case the company has warehouses and distribution centers for merchandise subject to foreign trade, outside the production and/or manufacturing facilities belonging to it, these must be subject, according to their characteristics, to what is established in this document, with the object of maintaining integrity in its supply chain. Response: Explanatory Notes: According to the process mapping of its merchandise, if in the logistics chain of foreign trade merchandise it is considered to move to a warehouse or distribution center, these must comply with the minimum security requirements established by the AGACE. In such a way, they are obliged to fill out a Company Profile for each of these mentioned installations.
Therefore, indicate how many warehouses and/or distribution centers it uses, provide their general data (name and address), and briefly explain what activity is carried out in this installation. Additionally, include also those warehouses and/or distribution centers that are used for national products, or fixed assets, as reference (these will not have to fill out a Company Profile). Likewise, indicate if these belong to the company or is a service contracted through a third party. In this case, according to the supplier selection criteria mentioned regarding Commercial Partners, indicate how it ensures that they comply with the minimum security requirements (warehouses and/or distribution centers managed by a third party are not obliged to present a Company Profile).
5.3 Cargo delivery and receipt. The company must ensure the identification of transport medium operators that carry out the delivery or receipt of the cargo. Likewise, the company must designate a person responsible for supervising the loading or unloading of the shipment, verifying the detailed description of the merchandise, weight, labels, marks, and quantity, comparing this information with the corresponding purchase or delivery orders. Likewise, the driver transporting the merchandise must be provided with the required documentary information for its correct transport, which includes, in an enumerative but not limiting manner, destination, route to be maintained, contact data, and/or procedure in case of any security incident or inspection by any authority, among others. When the cargo is stored overnight or during a prolonged period in the shipping area, measures must be taken to secure the cargo against unauthorized access; said area must be monitored by its alarm and closed-circuit television and video surveillance systems and have restricted access. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to guarantee that these areas remain free of visible pest contamination. During the cargo loading and unloading process, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise, or pests), and record said review (incident reports, records, reports, etc.) as evidence that the high-security seal and/or lock was placed correctly; digital photographs must be taken at the moment of loading the vehicles. To the extent possible, these images should be sent electronically to the destination or merchandise delivery contact point for verification. Also, the personnel responsible for the shipping and/or receiving area must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on the identification of common errors in export shipment documentation, with the objective of preventing these from resulting in security incidents or suspicious merchandise. In case of having own cargo transport, it must provide training to transport operators to review import and/or export documentation in order to identify or recognize suspicious cargo shipments, such as: a) Originating or destined to unusual places; b) Different routes; c) Cash payments; d) Observing unusual shipping and/or receiving practices; e) Lack of information.
Response: Explanatory Notes: Attach the documented procedure indicating the procedure for the delivery and receipt of cargo and ensure it includes the following points: a) Method to identify transport operators. b) Documentation delivered to operators. In addition to transport documents and customs documents (Bill of Lading, manifests, etc., which must be presented to the authority in a legible, complete, accurate, and timely manner), there must be a record accompanying the entry and exit of goods, which includes:
5.5 Report of discrepancies in cargo. There must be documented procedures to detect and report missing, surplus, prohibited merchandise or any other discrepancy in the delivery or receipt of goods, which must be investigated and resolved. It must be verified that the cargo matches what is indicated in the description declared in the packing list or the shipping document, specifying the detailed description of the goods and the data that allow their correct identification and quantification. Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of goods and ensure it includes the following points: a) Persons responsible for carrying out the review. b) Documents to be checked. c) Areas to which the information is reported. This procedure must be applied both to the merchandise received from import; if applicable, in the review at intermediate points; as well as in the final delivery of the goods to its client. 5.6 Processing of cargo information and documentation. The company must have documented procedures to ensure that the electronic and/or documentary information used during the movement and clearance of cargo, as well as the information received from business associates, is legible, complete, accurate, reported in time, and protected against changes, loss, or introduction of erroneous information. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use. Response: Explanatory Notes: Describe the procedure for processing cargo information and documentation, ensure you include the following points: a) Detail how it transmits relevant information and documentation regarding the transfer of its cargo with all those involved in its supply chain (indicate if it uses a specific computer control system and briefly explain its function). Likewise, detail how it validates that the provided information is legible, complete, accurate, reported in time, and protected against changes, loss, or introduction of erroneous information. b) Forms and documentation related to import and/or export must be secured to prevent unauthorized use. c) Indicate how business associates transmit information to the company and how they ensure its protection.
5.7 Inventory Management, control of packaging, container, and packing material. The company must have documented procedures for inventory control and storage of cargo and periodic reviews and audits must be carried out to verify their correct management. Likewise, it must have a documented procedure for the control of packaging, container, and packing material of the goods, which must also include the procedure for control, dissemination, and prevention of visible pest contamination, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports or platforms) to stack, move, and protect the cargo throughout its entire supply chain. Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, among other aspects according to its operation: a) The frequency with which it carries out stock verification (periodic inventory). Indicate if there is a documented scheduled calendar to perform them. b) Indicate what is done in case of excesses and shortages in inventories. c) Indicate the treatment given to the control and handling of packaging, container, and packing material, and if applicable, of shrinkage, waste, or surplus material, which must also include the procedure for control, dissemination, and prevention of visible pest contamination, in the case of use of wooden packing materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports or platforms) to stack, move, and protect the cargo. This point is also focused on reducing the risk of introduction or dissemination of quarantine pests of importance to the country through packaging (imports), therefore, describe how it complies with the provisions indicated by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144 SEMARNAT-2017, in accordance with International Phytosanitary Standard No. 15 entitled Regulation of Wood Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. d) Indicate how the fumigation process is carried out to kill, inactivate, sterilize, devitalize, or eliminate pests. What actions are taken in case quarantine of packing materials is required. e) Indicate the area or person responsible for carrying out this process, as well as the documentation or certificate.
The applicant's procedures may include: a) Warehouse only accessible to authorized personnel. b) Frequency of stock control. c) Control of incoming goods, transfers to other warehouses, permanent and temporary withdrawals. d) Actions taken if irregularities, discrepancies, losses, or thefts are identified. e) Treatment of deterioration or destruction of goods. f) Separation of various types of goods, for example, high value or dangerous. 6. Customs management. The company must have documented procedures in which internal and operational policies are established, as well as the necessary controls for the due compliance of customs obligations. Likewise, it must have specialized personnel and documented procedures establishing the verification of the information and documentation generated by the customs broker or, if applicable, ensure the processes performed by the customs representative. 6.1 Customs clearance management. The company must have a documented procedure in which the criteria for the selection of a customs broker or, if applicable, a customs representative are established, who, according to national legislation, are authorized to promote the clearance of goods on behalf of others. Response: Explanatory Notes: Describe the selection and evaluation procedure of the customs broker or representative and ensure it includes the following points: a) Selection criteria. b) Evaluation methods and periodicity. c) Describe the indicators with which it evaluates the service of customs brokers. Indicate the full name and the patent and/or authorization number of the customs broker or representative authorized to promote its foreign trade operations. 6.2 Customs obligations. The company must have a documented procedure establishing how it maintains updated control of foreign trade goods inventories as established in Article 59, fraction I of the Law and the information referred to in Annex 24, sections I and II, as applicable. The company must have a documented procedure for compliance with customs obligations derived from foreign trade operations carried out. This must include, at least, compliance with what is established in Article 59, fractions II and III of the Law, which will allow verification of the origin and provenance of the goods, through a control that allows identifying the country of origin, the Free Trade Agreement or Commercial Agreement from which the tariff preference was applied, and the document that supports said preference, in case of applying a tariff preference according to a self-certification, having all the elements that accredit the origin of the goods, as well as the correct determination of the customs value.
These procedures regarding the origin of the goods must describe the cases in which the origin of the goods is declared and the documentation with which the origin character must be demonstrated. In the case of companies that introduce goods into the national territory under a deferral program or tariff refund program, the company must have a procedure in which it describes how it determines the payment of foreign trade taxes, according to what is provided in the Treaties of which Mexico is a party, in accordance with what is established in Article 63-A of the Law. In the case of having a development program authorized by the SE, it must have documented procedures to comply with what is required in the same, among which are inventory control, return deadlines, and restrictions regarding the change of destination of temporarily imported merchandise, among others established in Article 24 of the IMMEX Decree, as well as the Annual Report of Foreign Trade Operations referred to in Article 25 of said decree. Response: Explanatory Notes: Attach the procedure by which it establishes how it maintains updated inventory control in terms of fraction I of Article 59 of the Law. Attach the procedure to comply with customs obligations derived from the verification of the country of origin and the valuation of foreign trade goods in terms of fractions II and III of Article 59 of the Law. Regarding this, for the effects of restrictions on the refund of customs duties on exported products and on customs duty deferral programs, origin only needs to be demonstrated when the imported merchandise is originating and is subsequently sent to another signatory party of the International Treaty or Commercial Agreement in question. Regarding countervailing duties, origin must be demonstrated when the tariff fraction of the imported merchandise is subject to such measures. And origin must also be demonstrated regarding merchandise imported with preferential tariff treatment under an International Treaty or Commercial Agreement of which Mexico is a party. Origin will be considered demonstrated when the company has the certificate of origin or other document provided for in the applicable provisions. Indicate if it has an IMMEX Program authorized by the SE, and if applicable, attach the procedure to comply with the obligations established in Articles 24 and 25 of the IMMEX Decree, among which are, by way of example and not limitation, the following: a) Register where productive processes are carried out. b) Return of goods within authorized deadlines. c) Automated inventory control. d) Annual Operations Report, among others. In case of having any other export promotion program, attach the procedure to comply with the obligations derived from it.
6.3 Customs Verification. The company, in order to guarantee compliance with the mandate entrusted to a third party, as well as to verify the truthfulness of the information declared in its name before the competent authorities, must have documented procedures so that the personnel designated by the company periodically verify that the declarations registered in its accounting match what appears registered in the SAAI Web, and, where applicable, report to the customs authority any discrepancy in such information. The company, likewise, must have a procedure for the filing of declarations for their adequate control.
Likewise, the company must have documented procedures, in which the periodic verification of the correct tariff classification of goods subject to foreign trade and the verification of the tariff and non-tariff regulations and restrictions to which they are subject are established.
Response: Explanatory Notes: Attach the procedure established to verify the information that appears registered in the SAAI Web, and cross-reference it with the declarations and documentation requested from the customs broker and/or customs agent. Attach the documented procedure for the verification of the correct tariff classification and NICO. This must include, among other aspects according to its operation: a) Method for the review and verification of the tariff classification and NICO of the goods and their corresponding tariff rates, regulations, and non-tariff restrictions. b) Maintenance of an updated file of foreign trade products. Detail which items are concentrated in it (tariff fraction, NICO, Rates, Regulations, Opinions, among others) and with what periodicity it is updated. c) The tools, systems, programs, or technical information used to classify its goods. d) Report to the corresponding areas the changes in the tariff fractions and the implications that are generated in rates and regulations; likewise, when it comes to changes in the NICO.
For the above, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the point of origin of the goods. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must meet or exceed the ISO 17712 Standard for high-security seals.
With the objective of maintaining supply chain security, the company must systematically inspect all cargo vehicles upon entry and exit from its facilities (domestic and international traffic), in addition to keeping a record.
7.1 Cargo Integrity and Use of Seals in Containers and Trailers. The company must have a documented procedure where the means of transport are identified and, where applicable, the containers, train cars, and/or semi-trailers used in its international logistics chain, and indicate how their integrity is maintained.
For the above, as one of the security mechanisms, the company must use high-security padlocks or seals that meet or exceed the ISO 17712 Standard in all containers and loaded trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. For this, the company must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when opened by any authority. In the event of such an inspection, drivers must notify and register any unusual anomaly or structural modification found in the means of transport resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to the commercial partners involved in the supply chain, and the investigation of the security incident. These must be notified to security personnel, commercial partners that may be part of the affected supply chain, security specialist, or Authorized Economic Operator Program contact.
Likewise, it is necessary to have a documented procedure for the administration of the same, which must include the control, assignment, safeguarding, handling of discrepancies, and destruction of seals and padlocks. Regarding the supplier of the seals and/or padlocks, it must be demonstrated how these comply with the ISO 17712 Standard. The company's management or a security supervisor must perform periodic and documented audits of the high-security seals and/or padlocks; these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-check with inventory records and shipping documents. Also, supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and Instruments of International Traffic to corroborate that the information is correct.
Response: Explanatory Notes: Detail the type of vehicles, means of transport, as well as containers and semi-trailers that the company uses for the transfer of its goods (maritime containers, dry boxes, railway containers, tanks, among others). Indicate if the transport units, containers, and/or trailers are owned by the company or a third party. Indicate the transport companies hired to carry out the transfer of foreign trade goods, indicating their name or corporate name, RFC, and tax domicile. Attach the documented procedure for the placement and review of seals and/or padlocks in vehicles, means of transport, containers, train cars, trailers, and/or semi-trailers. This must include, among other aspects according to its operation: a) Verify that the seal or padlock is intact and determine if there is evidence of improper manipulation. In case of using a high-security padlock, (bottle type, cable, padlock, etc.), it must use the VVTT inspection method:
b) Review and cross-reference the documentation containing the number of the original seal or padlock and, where applicable, of the additional ones carried during the transfer of the goods. In case of using the replacement seal and/or padlock, said number must be registered within the company's control. If altered seals and/or padlocks are identified, they must be kept to help carry out the investigation of said incident or discrepancy and, as appropriate, report the compromised seals and/or padlocks to the foreign authority. c) If the company uses cable seals, these must be placed on the two vertical bars of the container. d) Review that the closing devices, hinges, and pins are attached to the trailer or container and welded or riveted. Also, protective plates can be placed on the door hinges and/or a seal/adhesive tape can be placed on at least each side. Likewise, the correct functioning of handles, latches, and all other locking or closing mechanisms of the cargo vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device. e) Indicate how they assign and replace high-security padlocks, in the case that, during the trip, it is inspected by another authority. If a seal and/or padlock breaks in transit, the cargo must be examined, the number of the replacement seal and/or padlock must be registered, and the driver must immediately notify business associates when this happens, indicate who broke it and provide the new seal number. Attach the documented procedure for the control and handling of seals and/or padlocks. This must include, among other aspects according to its operation: a) What type of seals and/or padlocks it uses in its operations (foreign trade, transit, storage, etc.). b) Who has access and how padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a safe place, have an inventory, control of their distribution, and tracking (record of seals used, as well as the receipt of new seals and/or padlocks).
c) Describe how the company's management or security supervisor participates in the audits of high-security seals and/or padlocks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how supervisors of the shipping area and/or warehouse managers verify seal numbers used in means of transport and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). d) How discrepancies in seal and/or padlock numbers are addressed. e) Indicate who the supplier(s) is/are and how it is proven that the specifications of the seals and/or padlocks comply with the ISO 17712 Standard (attach certificate issued by the certifying company in charge of verifying compliance with the corresponding ISO).
All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees in charge of executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of means of transport, containers, train cars, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of the means of transport, container, train cars, trailers, and/or semi-trailer used as Instruments of International Traffic, even the reliability of the door lock mechanisms, in order to identify natural or hidden compartments.
Inspections of means of transport or cargo vehicles, containers, and trailers (land or railway cargo) must be systematic and carried out upon entry and exit from the company and, where applicable, at the cargo loading point; and if the infrastructure allows, before arriving at the customs office for dispatch using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by alarm and closed-circuit television and video surveillance systems; said system must cover the inspection process in its entirety.
The documented procedure for its inspection must include, by way of example and not limitation, the following review points:
Means of Transport Trailers, Train Cars, Semi-trailers, and Containers
For means of transport with a trailer or integrated cargo compartment, the items indicated in the Trailers section must be added to the means of transport points.
Likewise, before loading the means of transport, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide smuggling or have been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of goods subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination. The driver must ensure before crossing that the cabin is clean and free of trash.
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of means of transport, containers, trailers, and semi-trailers. This must include, among other aspects according to its operation: a) Persons responsible for carrying out the inspection. b) Definition of the place or places where the inspection is carried out and indicate how the monitoring is performed by alarm and closed-circuit television and video surveillance systems. c) The review points for means of transport, trailers, semi-trailers, and containers for both security and quality and agricultural inspections whose purpose is to look for visible pests. d) Instructions for the driver to ensure before crossing that the cabin is clean and free of trash. Attach the established format for the inspection of means of transport or cargo vehicles, containers, train cars, trailers, and/or semi-trailers. If you use other types of cargo vehicles for the transport of your goods (vans, pickup, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points.
Likewise, the security and agricultural inspection format must include the following information: a) Date of inspection; b) Time of inspection; c) Vehicle license plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected; and f) Name and signature of the employee who performs the inspection and of the supervisor.
The security and agricultural inspection format of containers and Instruments of International Traffic must be part of the import and export documentation.
The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
Additionally, and based on risk analysis, the company should perform periodic random reviews of cargo vehicles after the transport personnel has performed security inspections to verify that they have been carried out correctly, counter internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the means of transport may be susceptible to contamination. Indicate if the repair or maintenance of transport units, containers, or trailers is carried out in the same facilities or is carried out with an external provider. Describe how it validates that the cargo vehicles, containers, trailers, and semi-trailers used as Instruments of International Traffic, that transport its goods, meet the necessary physical-mechanical conditions for their transfer and crossing, in addition to validating that they have records of this type of maintenance for at least one year.
7.3 Storage of vehicles, means of transport, containers, train cars, trailers, and semi-trailers. In the event that the means of transport, containers, trailers, and/or semi-trailers that will be destined to transport foreign trade goods are empty and must be stored in parking areas, they must be secured with a padlock and/or indicative seal, or in a safe area that is guarded and/or monitored.
When it is necessary to store or overnight any loaded container, trailer, and/or semi-trailer, it must be in a safe area that has perimeter barriers and is monitored by alarm and closed-circuit television systems, to prevent unauthorized access and manipulation of the merchandise, for which it must be closed with a high-security padlock according to the ISO 17712 Standard.
Response: Explanatory Notes: Indicate if the company stores the containers, trailers, and/or semi-trailers for their subsequent dispatch, or in the case of those that are empty and how it maintains their integrity within its facilities: a) In case of using padlocks and/or seals, for empty containers, trailers, and semi-trailers, indicate what type it uses. b) In case of using any container, trailer, and/or semi-trailer as a storage facility for raw material and/or any other type of goods, indicate how it maintains their integrity and security.
Likewise, there must be continuous training programs for personnel that disseminate the company's security policies, as well as the consequences and actions to be taken in case of any fault or security incident.
8.1 Verification of work history. The company must have documented procedures to investigate and verify the information recorded in the curriculum, criminal records (if local legislation and company policies allow it), and applications of candidates with possible employment, in accordance with local legislation, either on its own or through an external company.
Likewise, for positions that by their sensitivity so require and affect the security of shipments that are subject to foreign trade, in accordance with its previously carried out risk analysis, stricter requirements for their hiring must be considered, which must be carried out periodically. Regarding personnel who already work in the company, periodic investigations must be carried out based on the activities and/or sensitivity of the employee's position.
All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for the hiring of personnel, and make sure to include the following: a) Requirements and documentation required. b) Tests and exams requested. Indicate the areas and/or critical positions that have been identified as risky, according to your analysis, and indicate the following: a) Indicate what the additional requirements are for specific areas and/or jobs, such as: criminal records (if local legislation and company policies allow it), certificate of non-criminal record, socioeconomic studies, clinical studies, toxicological (drug use), etc. In its case, indicate the positions or work areas in which they are required and with what periodicity they are carried out. b) Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. In case of hiring a service agency for the hiring of personnel, indicate if this has documented procedures for the hiring of personnel and how it ensures that they comply with the same. Briefly explain what they consist of. The procedures for the hiring of personnel and contractors may include: a) Exhaustive investigations of the work and personal background of new employees. b) Confidentiality and liability clauses in employee contracts. c) Specific requirements for critical positions.
d) Where applicable, the periodic update of the socioeconomic and physical/medical study of employees who work in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. The company may consider the results of candidate background checks, as permitted by current legislation, to make hiring decisions. Background checks are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Procedure for employee termination. There must be documented procedures for employee termination that include the delivery of identification and any other items provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Furthermore, this procedure must include the deactivation in those computer systems, access systems, among others that may exist.
Response: Explanatory Notes: Describe the procedure for employee termination, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the delivery of identification, uniforms, keys, and other equipment is performed and confirmed. c) Indicate the control, record, and/or format in which the delivery of material and deactivation in computer systems (if applicable) is identified and ensured (attach, if applicable). d) Specify the type of records of personnel who ended their employment relationship with the company, so that in case it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The company must maintain an updated system, control, or database of active employees. Likewise, it must perform and keep updated the records of affiliation to social security institutions and other legal labor records. In the case where the company has personnel contracted by its business partners and working within the facilities, it must ensure that they comply with the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate whether the company has an updated system, control, or database, both of personnel employed directly, as well as that contracted through a service provider company, and ensure it includes, by way of example but not limitation, the following information:
a) Full name. b) Updated photograph at least every 5 years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). d) Family ties. e) Work history. f) Illnesses. g) Medical exams. h) Training. i) Results of periodic evaluations. j) Observations. k) This personnel must be hired in accordance with current labor laws and regulations.
9.1 Document classification and handling. There must be procedures to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified and procedures for its destruction must be established. The company must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: a) Control register for delivery, loan, among others of documentation. b) Restricted access to the archive area. c) Storage and classification policies. d) An updated security plan that describes the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss thereof. e) In the case of electronic or digital information, it must adhere to the security criteria of the sub-standard of 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts that require periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards, which must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote user access. For the above, there must be written procedures and infrastructure to protect the company against losses, theft, leakage, hacking, and/or ransomware of information; this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access. If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how it backs up and ensures the security of its information, in addition to protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which information backups are carried out. b) Who has access to them and who authorizes the recovery of information. c) Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. d) Mention if to perform this type of tests or vulnerability scans, it does so through software, a third party or provider, and if so, indicate the name or corporate name. e) In case vulnerabilities are found, describe the corrective actions that must be implemented. f) Indicate if it shares information about cybersecurity threats with its business partners participating in its supply chain (for example: communications, bulletins, emails, etc.).
g) Systems must be protected by passwords and must be modified frequently; therefore, indicate the procedure to change them. h) Indicate if there are information security policies for their protection. i) There must be a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to its systems and/or Information Technology data (any system used by the company), as well as the abuse of policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology security systems and policies.
Information technology and cybersecurity policies and procedures must be reviewed annually and updated due to an attack or according to situations that may put the company's systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In case of allowing employees to use personal devices to perform the company's work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely. Indicate if business partners have access to the company's computer systems. If so, indicate what programs they use and how they control access to them. Indicate if the computer equipment has a backup power supply system that allows business continuity.
The procedures regarding the backup of the company's information must also include: a) How and for how long the data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in case of incident and how to recover information. c) Frequency and location of backup copies and archived information. d) If backup copies are stored in sites alternative to the facilities where the data processing center is located. e) Tests of the validity of data recovery from backup copies.
The procedures regarding the protection of the company's information must also include: a) An updated and documented policy for the protection of the company's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. b) Detail if it operates with multiple systems (headquarters/sites) and how those systems are controlled. c) Who is responsible for the protection of the company's computer system (responsibility should not be limited to one person, but to several, so that each can control the actions of the rest). d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to personnel authorized to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements. e) Indicate the elements or format that passwords for access to Information Technology systems and computer equipment must have, frequency of changes, if there are other authentication methods, and who or what area provides those passwords.
f) Indicate the name of the "firewall" and anti-virus used (include licensing related matters), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or with incorrect licenses (software and hardware). All computer equipment, electronic media (hard drives, cell phones, etc.), and information technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be disposed of, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage. g) In case of employee termination, access to computer equipment, telecommunications, and network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. h) Measures planned to handle incidents in case the system is compromised.
10.1 Training and awareness on threats. The company must have a training and awareness program on supply chain security policies directed to all its employees (operational and administrative) and, additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. Likewise, specific training must be offered according to their functions to help employees maintain cargo integrity, perform container, trailer, and/or semi-trailer reviews for agricultural and security purposes, receive and review mail and packages, prevent operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and how to report internal conspiracies, protect access controls, as well as training regarding smuggling, merchandise theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible pest contamination, etc. These topics must be established as part of new employee induction and periodically maintain update programs. Update training must be performed periodically, after a security incident, and when there are changes in the company's procedures.
In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train personnel on the company's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or ransomware of information), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee induction and periodically maintain update programs.
Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives.
Response: Explanatory Notes: They must have a training program on security and prevention of security incidents in the supply chain for all employees who work for the company (administrative, operational, direct or indirect). Briefly explain what the training program consists of and ensure you include the following: a) Brief description of the topics taught in the program. b) When they are taught (induction, specific periods, due to audits, security incidents, etc.). c) Frequency of training, as well as updates and reinforcement. d) Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all objectives of the same. e) Explain how employee participation in supply chain security issues is encouraged.
Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments; b) Smuggling hidden in natural compartments; c) Signs of pest contamination; d) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit; and e) Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with International Standard for Phytosanitary Measures No. 15, entitled Regulation of Wooden Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations and the identification of infested wood.
10.2 Awareness for transport medium operators. The company must make known to the operators of the transport media it uses for the transfer of goods destined for foreign trade, the security policies regarding agricultural inspection procedures and security of transport media, loading and unloading, handling of security incidents, change of locks in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of transport media must be trained to inspect cargo vehicles for such purposes. In the case where the transport service is provided by a business partner, it must ensure that operators and/or drivers know all the security policies and procedures established.
Response: Explanatory Notes: Describe the dissemination program on security in the supply chain focused on transport medium operators and ensure you include the following: a) Indicate how this dissemination is carried out. b) Specify the topics covered. c) In case of using the services of a business partner for the transfer of its goods, indicate how operators are informed of the company's security policies and procedures. d) Indicate how participation in supply chain security training of transport medium operators is documented (videos, attendance lists, brochures, etc.).
The topics that must include, by way of example but not limitation, are: a) Access and security policies at the facilities. b) Delivery-receipt of merchandise (which includes suspicious cargo shipments). c) Confidentiality of cargo information. d) Transfer instructions. e) Accident and emergency reports.
f) Instructions for the placement of high-security padlocks and/or seals in the event of inspection by other authorities, as well as the control and use of high-security seals and padlocks in transit (placement of a new one, review after an authorized stop, etc.). g) Installation and testing of security alarms and unit tracking systems, where applicable. h) Identification of authorized formats and documents to be used. i) Signs of hidden compartments. j) Concealed smuggling in natural compartments. k) Signs of pest contamination. l) Procedures to follow if something is found during an inspection of the means of transport or if a security incident occurs during transit.
11.1 Reporting of anomalies and/or suspicious activities. In the event of detection of anomalies and/or suspicious activities related to the security of the supply chain and in accordance with their logistical processes (related to access control, delivery, receipt and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners that may be part of the affected supply chain, security specialist or contact of the Authorized Economic Operator Program, and other competent authorities, keeping a record of such anomalies and/or unusual activities. Response: Explanatory Notes: Describe the procedure to report or denounce anomalies and/or suspicious activities, as well as those containing mechanisms to anonymously report problems related to security; ensure you include the following: a) Who is responsible for reporting incidents. b) Detail how it determines and identifies with which authority to communicate in different scenarios or presumption of suspicious activities. c) Mention if it keeps a record of the reporting of these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. Written procedures must exist to report or denounce anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that so require. This information must include the documentation generated to carry out the foreign trade operation of the affected goods that allows identifying each of the processes through which the goods passed, up to the point where the incident was detected, and that allows recognizing the vulnerability of the chain. Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in the event of any security incident and ensure you include the following: a) Person responsible for carrying out the investigation. b) Documentation that integrates the investigation file. The documents to be included in the file derived from the investigation, by way of example and not limitation, may be: a) General information of the shipment, purchase order. b) Transport request; confirmation of means of transport; identification of the transport operator (access records, exit, records of security inspections, etc.). c) Container inspection formats; exit order; delivery records. d) Videos from alarm systems, closed-circuit television, and video surveillance. e) Documentation generated for the carrier (packing list, bill of lading, instruction sheet). f) Documentation generated for business partners (description of goods, proformas, CFDI or equivalent documents, etc.) and customs authorities. g) Documentation generated by the business partner (customs declarations, manifests, tracking and inspection reports, videos if applicable, etc.). h) Tracking and monitoring report of the unit (GPS tracking).
E4. Customs Broker Profile. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization. General Information. The objective of this Profile is to ensure that the Customs Broker implements security practices and processes that help strengthen the supply chain by mitigating the risk of contamination in shipments with illicit products and likewise reducing the risk of incurring incidents during the customs clearance of goods. Customs brokers interested in obtaining the authorization referred to in rule 7.1.5. must have documented and verifiable processes. Likewise, the Customs Broker interested in the authorization must integrate the criteria required in this document into the business model or design they have established, seeking during the implementation of security standards, the application of an analysis culture that supports decision-making consistent with the values, mission, vision, codes of ethics and conduct of the Customs Broker itself. It is important to mention that the scope of the minimum security criteria required in this Profile is applicable to the essential operation performed by the Customs Broker, mainly to processes related to the customs clearance of goods. Likewise, and taking into account the variety of integrated logistical services that a Customs Broker can currently provide to its clients, certain additional criteria are contemplated to be met, specifically for customs brokers who concentrate or have holding yards and/or maneuvers for the means of transport of foreign trade goods in the same facilities where they provide their services. Filling Instructions:
You must fill out a Profile for each of the facilities associated with the customs office of assignment, as well as for each of the facilities associated with the additional customs offices of the customs patent. This information must coincide with what was stated in your application for Certified Customs Broker Commercial Partner.
Detail how the Customs Broker complies with or exceeds what is established in each of the sections as indicated.
The format of this document is divided into two sections, as detailed below:
Standard Description of the standard 1.1 Sub-standard Description of the sub-standard Response Explanatory Notes Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards; therefore, you must attach the procedures in Spanish; these procedures must be characterized by describing or defining the objective the document pursues, the start and end of the process, measurement indicators, requirements, documents or formats to be used, responsible parties, among others.
In cases where only an explanation of the procedure is required, it must be detailed and placed in the Response field. The field regarding the Explanatory Notes is a guide regarding the points that must be included in the Response of each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once this Customs Broker Profile has been answered, it must be attached to the Registration Application in the Enterprise Certification Scheme referred to in the first paragraph of rule 7.1.5., fraction II, subsection b). For the purpose of verifying what was stated in the previous paragraph, the SAT through the AGACE may carry out an inspection of the facility, with the exclusive purpose of verifying what was stated in this document.
Any incomplete Customs Broker Profile will not be processed.
Any question related to the Registration Application in the Enterprise Certification Scheme and the Customs Broker Profile should be directed to the contacts appearing on the SAT Portal.
In the event of being authorized with the Registration in the Enterprise Certification Scheme, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and as a result changes or modifications are required in the information stated and provided in this Customs Broker Profile to the authority, in accordance with what is established in rule 7.2.1., fourth paragraph, fractions I, II and VII.
For the renewal of the certified commercial partner, the procedure marked in rule 7.2.3. will be followed.
When, as a result of the inspection visit, non-compliance related to minimum security standards results, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the non-compliances indicated.
Installation Data A Customs Broker Profile must be filled out for each of the facilities associated with the customs office of assignment, as well as for each of the facilities associated with the additional customs offices under the customs patent. Customs Broker Information. Customs Broker Profile Number: from: Customs Broker Name: ____________________ Patent: ________________ Authorization: Assignment: _________ Assignment: ________________ Authorized Customs Offices (name): Name and/or Denomination of the installation: Type of Installation (administrative offices, facilities with goods storage or transport service, etc.): Street Number and/or exterior letter Interior Number and/or letter Neighborhood Postal Code Municipality/Delegation Federal Entity
Age of the Installation (years of operation) Predominant activity Types of services: Performs validation of customs declarations in this installation: No. of average monthly operations (EXP): (By means of transport, maritime, air, land, rail, etc.) No. of average monthly operations (IMP): (By means of transport, maritime, air, land, rail, etc.) Total number of employees at this installation: Installation Surface (m2): Security program certifications: (Indicate if this installation has a certification from any of the following programs) Supply Chain Security Programs Yes No Program: Registration: Certifying Body: Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk analysis. The Customs Broker must have measures to identify, analyze, and mitigate security risks throughout the supply chain, including its installations. For the above, it must have a written and verifiable procedure to determine the risk in all its operations, based on its organization's model (example: location of installations, type of goods and country of origin, volume, clients, suppliers, routes, hiring of personnel, classification and handling of documents, Information Technologies, potential threats, etc.) that allows it to implement and maintain appropriate security measures. Based on the above, the Customs Broker must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be executed at least once a year, so that it allows permanently identifying other threats or risks considered in its operation and in the supply chain, as a result of some incident or when they originate from changes in the initial conditions of the Customs Broker's installations and processes, as well as to identify that the policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the Company's Security Committee designated by the Customs Broker must participate in the elaboration and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program. Response: Explanatory Notes: Indicate what are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in its daily operations throughout the supply chain and in its installations, which must include as a minimum the following points. a) Periodicity with which it reviews and/or updates the risk analysis. b) Aspects and/or areas that the Customs Broker incorporates into the risk analysis. c) Methodology or techniques used to perform the risk analysis. d) Responsible parties for reviewing and/or updating the company's risk analysis. Likewise, the documented procedure to identify risks in the supply chain and its installations must contemplate the risk appreciation and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Identification of risks in its supply chain and its installations. c) Risk analysis (causes, consequences, probabilities, and existing controls to determine the risk level as high, medium, and low). d) Risk evaluation (decision-making to determine the risks to treat and priority to implement treatment). e) Risk treatment (application of alternatives to change the probability of risks occurring). f) Risk monitoring and review (monitoring of risk analysis results and verification of the effectiveness of its treatment). It is suggested to use administration, management, and risk evaluation techniques according to international standards ISO 31000, ISO 31010, and ISO 28000 that, according to its business model, should be implemented.
1.2 Security policies. The customs broker must have policies oriented to prevent, secure, and recognize threats in the security of the supply chain and installations, such as drug trafficking, money laundering, arms trafficking, human smuggling, prohibited goods, acts of terrorism, as well as in the exchange of information, reflected in the corresponding procedures. To promote a security culture, the Customs Broker must demonstrate its commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The Customs Broker must endorse and sign the security policy. Response: Explanatory Notes: Enumerate the policies in matters of security oriented to prevent, secure, and recognize threats in the supply chain and the Customs Broker's installations, who is responsible for their review, signature, and dissemination to employees, as well as the periodicity with which its update is carried out. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by the Customs Broker and displayed in various areas of the installation, including the Customs Broker's website, posters in key areas of the installation (reception, import and/or export, human resources, etc.), and as part of initial and reinforcement training.
1.3 Internal audits in the supply chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year that allows evaluating all processes in matters of security in the supply chain in a more critical and profound way, as well as guaranteeing that its employees follow the Customs Broker's security procedures. The audits must be carried out by the Security Committee and a documented procedure must be established, as well as a program or calendar for their realization. Although it is necessary that the audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, risk level, business model, and variations between installations. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the Customs Broker's security procedures. The review process does not have to be complex; however, the formats and records used for the application of said reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the follow-up and closure of preventive, corrective, and improvement actions identified. The senior management of the organization must review the results of the audits, analyze the causes, and undertake the required corrective and/or preventive actions. The audit process must guarantee that the necessary information is collected to allow management to make this evaluation. The review must be documented, in addition to the fact that the Customs Broker's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation. Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain; ensure you include the following points: a) Indicate how the scheduling or calendarization is carried out to perform an internal audit in matters of security in the supply chain, which has been implemented by the Customs Broker. b) Indicate who participates in it, and the records that are made of it, as well as the periodicity with which they are carried out. c) Indicate how the management or the Customs Broker verifies the results of the security audits, how it carries out and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure of the same. d) The formats used during internal audits must be duly filled out, and through them, evidence that the procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans. A documented contingency and/or emergency plan must exist; this plan must address crisis management, security recovery plans, and the resumption of the organization related to supply chain security and its facilities to ensure business continuity in the event of a situation affecting the normal development of activities and foreign trade operations. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, fire, kidnapping of a transport driver by armed individuals, customs closure, bomb threat, detection of suspicious packages, power outage, theft and/or damage to goods, threats or extortion, blockades or road closures, among others. Such plans must be communicated to administrative and operational staff through dissemination programs and periodic training, as well as conducting tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness. Records of these must be properly filled out and signed (for example: result reports, minutes, or reports which must be supported by video recordings, photographs, etc., demonstrating their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level. Response: Explanatory Notes: Attach the documented procedure or contingency and/or emergency plan related to supply chain security and its facilities, to ensure business continuity in case of an emergency or security situation that affects the normal development of foreign trade activities (cancellation or suspension of patent, customs closure, foreign trade activities considered risky according to your analysis, acts of terrorism, blockades, robberies, accidents, etc.). This procedure must include, by way of example and not limitation, the following: a) What situations it contemplates, describing the action plan and steps to be followed in case of crisis, as well as the tasks assigned to staff during the handling of such contingencies. b) What mechanisms it uses to disseminate and ensure these plans are effective. c) Contemplate the scheduling and execution of tests, practical exercises, and annual drills and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution).
2.3 Perimeter Walls. Perimeter walls and/or peripheral barriers must be installed to secure the perimeters of the Customs Broker's facilities, based on a risk analysis. In the case of having a yard for transport means of goods located in the same facilities, it must be delimited, as well as the place where any maneuver and/or handling of cargo takes place as appropriate. These must be inspected regularly and keep a record of the review with the purpose of ensuring their integrity and identifying damage, which must be repaired as soon as possible by the personnel designated for these tasks. Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls with which the Customs Broker's facilities are equipped, ensure you include the following points: a) Indicate the characteristics of the same (material, dimensions, etc.). b) In case of not having walls, justify the reason in detail. c) Frequency with which the integrity of the perimeter walls is verified, and the records that are kept with the purpose of ensuring their integrity and identifying damage, which must be repaired as soon as possible. d) Indicate the personnel or area responsible for carrying out inspection and damage repair tasks. In case of having a yard for transport means in your facilities, describe how it is delimited. The procedure for the inspection of perimeter walls may include: a) Personnel responsible for carrying out the process. b) How and with what frequency the inspections of fences, perimeter walls, and/or peripheral barriers and buildings are carried out. c) How the inspection record is carried out. d) Who is responsible for verifying that repairs and/or modifications meet the technical specifications and necessary security requirements.
2.4 Parking Lots. In the case of having parking lots in the facilities, access to them must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking, in their case, within the yard for transport means, as well as in adjacent areas. Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots, ensure you include the following points: a) Those responsible for controlling and monitoring access to parking lots. b) Identification of parking lots (if applicable) specify if employee and visitor parking is separated from storage and goods handling areas. c) How entry and exit control of vehicles to the facilities is carried out. Indicate the records made for parking control, existing control mechanisms, for example: badges, card readers, lanyards, etc., how they are assigned and the responsible area for doing so. d) Policies or mechanisms (if applicable) to not allow the entry of private vehicles to storage and goods handling areas. 2.5 Key and Lock Device Control. Windows, doors, as well as inner and outer fences must be secured with locking devices; these devices must be implemented based on the Customs Broker's risk analysis. Likewise, the Customs Broker must have documented procedures for the handling, storage, assignment, and control of keys in the facilities, keeping a record and establishing signed responsibility letters by persons who have keys or authorized access according to their level of responsibility and tasks within their work area. Response: Explanatory Notes: Indicate if all doors, windows, inner and outer entrances have closing or security mechanisms. Attach the documented procedure or procedures for the control, storage, assignment, and handling of keys and/or closing devices of the facilities, offices, and inner areas. Ensure that these procedures include the following points: a) Those responsible for administering and controlling key security. b) Format and/or control record for key lending. c) Treatment of loss or non-return of keys. d) Indicate if there are areas where access is with electronic devices and/or some other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of people, material, and/or equipment located there, including the following areas: entrances, exits, perimeter walls and/or peripheral barriers, inner fences, and parking areas if applicable. An emergency and/or backup system must be available in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: a) Indicate which areas are illuminated and which have a backup system (Indicate if you have an auxiliary power plant or some other mechanism to supply electricity in case of any contingency). b) How you ensure that the lighting system has continuity in the event of supply failure in each of the areas of the facilities, in such a way that it allows clear identification of the personnel, material, and/or equipment located there. c) Person responsible for controlling the lighting systems. d) Maintenance and review program (if it coincides with another process, indicate it). The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting. 2.7 Alarm systems, closed-circuit television, and video surveillance systems. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must be used to watch, notify, or deter unauthorized accesses and prohibited activities in the facilities and other areas considered sensitive, notify the corresponding area, in addition to being used as a tool of proof in investigations derived from any security incident. These security systems and technologies must be placed according to a prior risk analysis in such a way that areas involving the access of personnel, visitors, and suppliers are watched and monitored, and in its case, the access areas for passenger vehicles and cargo vehicles and others considered sensitive. Such systems must allow clear identification of the area or environment being watched, be permanently recording, and keep a backup of recordings for at least one month, with the purpose of having the necessary elements to assign responsibilities in case of a security incident. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must have a documented operation procedure that includes the supervision of the good condition of the equipment and the verification of the correct position of the cameras, indicating the frequency with which the backup of recordings must be performed, as well as those responsible for their operation. Such a system and all security technology infrastructure must have restricted access.
Response: Explanatory Notes: Mention the documented procedure indicating the functioning of the external central alarm system or sensors, and in its case, describe the following points: a) Indicate if doors and windows have alarm sensors, as well as the areas where motion sensors are available. b) Procedure to follow in case an alarm is activated. c) Indicate the personnel, responsible area, or service provider for maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, and video surveillance systems, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensure you include the following points: a) Indicate the number of security cameras of the alarm systems, closed-circuit television, and video surveillance systems installed, technical characteristics, and their location. Detail if it covers the entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as the place of vehicle storage). Attach a layout or distribution map of the security cameras. b) Indicate the location of the alarm systems, closed-circuit television, and video surveillance systems, and security technologies, where the monitors are located, who reviews them, as well as operating hours, and in its case, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Periodic and random reviews of recordings must be carried out. Indicate how they review them (random, every week, special events, restricted areas, etc.), who is the designated personnel, and how they are involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes.
d) Indicate for how long these recordings are kept (must be at least one month). e) Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must have an alternative energy source that allows them to continue functioning in case of unexpected loss of direct power. Therefore, indicate if the alarm systems, closed-circuit television, and video surveillance systems, and security technologies are backed up by an electrical power plant or some other mechanism to supply electricity that guarantees their functioning. These systems should have an alarm/notification function, indicating a failure condition in functioning and/or recording, indicate if your systems have such a function. f) Indicate if in addition to the alarm systems, closed-circuit television, and video surveillance systems, you use some other type of technology to strengthen the security measures you already have. g) Describe the procedure implemented to regularly test and inspect alarm systems, closed-circuit television, and video surveillance systems, and security technologies to ensure their good functioning. The results of the inspections and functioning tests must be documented, as well as necessary corrective actions (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a sufficient time for audit purposes. h) Indicate if the provider of the alarm systems, closed-circuit television, and video surveillance systems, has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for such monitoring.
3.2 Identification of employees, visitors, and suppliers. There must be an identification system for employees, visitors, and suppliers for the purpose of access to the facilities. Employees should only have access to those areas they need to perform their functions. Access to sensitive areas must be restricted according to the job description or assigned tasks. Visitors and suppliers must present official identification with a photograph for documentation purposes upon arrival, and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by personnel working with the Customs Broker during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. The management or security personnel of the Customs Broker must properly control the delivery and return of identification badges for employees, visitors, and suppliers, and ensure that they always wear the provided identification in a visible place. This procedure must be documented, as well as the procedures for the delivery, return, and change of access devices (for example, keys, badges, and/or credentials, proximity cards, etc.). Response: Explanatory Notes: Attach the documented procedure for the control of identifications. Describe the procedure for the identification of employees and ensure you include the following points: a) Identification mechanisms (badge and/or credential with photo, uniform, access control, biometrics, proximity cards, etc.). b) Identify if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable). c) Indicate how personnel contracted by a business partner, working within the facilities (contractors, subcontractors, etc.) is identified. The procedure must also describe how the Customs Broker delivers, changes, and withdraws employee identifications and access controls and ensure you include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Describe the procedure for the access control of visitors and suppliers, ensure you include the following points: a) Indicate what records are kept (personal forms for each visit, logbooks, among others). b) The record of visitors and suppliers must include the following:
Date of the visit;
Name of the visitor;
Identification number with photo (official documents, such as: driver's license, passport, INE, etc.);
Entry and exit times;
In the case of vehicular access, the format must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.). c) Identify who is the person responsible for accompanying the visitor and/or supplier, and whether there are restricted areas for their entry.
3.3 Procedure for identification and removal of unauthorized persons or vehicles. The Customs Broker must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles; said procedure must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: a) Responsible personnel. b) Designate a person or area responsible for being informed of security incidents. c) Instructions for confronting and directing unidentified personnel. d) Indicate in which cases the corresponding authorities must be reported to. e) Indicate how the recording of incidents and the measures taken in each case is carried out.
3.4 Courier and package deliveries. Courier and package deliveries intended for the Customs Broker or their personnel must be examined upon arrival and before being distributed to the corresponding areas and destinations. Likewise, the Customs Broker must have a documented procedure for the receipt and review of courier and package deliveries, which must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and package deliveries and ensure you include the following: a) Personnel in charge of carrying out the procedure. b) Indicate how the personnel or supplier of the courier and package delivery service is identified (indicate if an additional procedure to the supplier access procedure is required). c) Indicate how the review of the courier and/or packages is carried out, what mechanism is used, the records kept, and in case of detected incidents. d) Describe the characteristics or elements to determine which courier and/or package delivery is suspicious. e) Indicate what action is taken in the case of detecting suspicious courier and/or packages.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorist financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the Customs Broker must avoid contracting them and, in case, notify their security specialist or contact of the Authorized Economic Operator Program and the corresponding authority about their suspicions. The Customs Broker must have a written procedure for the identification of vulnerable activities established in Article 17, fraction XIV, as well as for compliance with the obligations established in Article 18 of the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (LFPIORPI). Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new commercial partners, and monitoring of partners already working with them; this includes any type of client and supplier that has a commercial relationship with the Customs Broker and ensure you include the following points: a) What information is required from its commercial partner. b) What aspects are reviewed and investigated (the result of the investigation must be integrated into the file). c) The indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be dispatched; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to indicating all those alerts to determine that a commercial partner is not reliable and thus, conduct a deeper investigation and evaluate if one should work with them.
d) Indicate if you maintain a physical or electronic file of each of your commercial partners, as well as the information it must contain. e) In the case of suppliers, indicate how the services of its commercial partner are evaluated and what points are reviewed. Likewise, the files for each of them must contain at least the documents that identify them fiscally and administratively depending on the type of relationship with the commercial partner. Considering the following: a) Granted mandate: It will be issued in original independent of the one delivered electronically, for each foreign trade operation carried out. b) Copy of the mandate or power of attorney of the legal representative, in case. c) Certified copy of the company's articles of incorporation (properly identified before the Public Property and Commerce Registry). d) Registration in the RFC of the importer or exporter. e) Notice of change of fiscal address, in case. f) Copy of official identification with photograph of the importer/exporter and of the legal representative, in case of being a legal entity. Attach the documented procedure to comply with the LFPIORPI, which must contain at a minimum: a) Actions to take when any of the vulnerable activities marked in the cited Law are identified. b) Notices to the SHCP. c) Integration of files of clients susceptible to this Law. The file must include at a minimum the following: a) Company data (name, RFC, activity, etc.). b) Legal representative data. c) Proof of address. d) Commercial references. e) Contracts, agreements, and/or confidentiality agreements. f) Security policies. g) In case, certificate or certification number in the security programs to which it belongs.
4.2 Security requirements. The customs broker must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in its supply chain such as transporters, private security companies, providers of loading and unloading services for merchandise, correspondent agencies, as well as those resulting from the analysis carried out. As well as from providers of cleaning services, cafeteria, private security, personnel contracting, high-security seal suppliers, collection and recycling, among others. The requirements must be based on the minimum security requirements established by the AGACE, or in case they exist, the specific Profile for each actor of the supply chain that corresponds to them. The Customs Broker must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in the Customs Broker Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation that supports compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the Customs Broker must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of commercial partners that provide a service within the facilities of the Customs Broker, they must be obliged to comply with these supply chain security requirements. Response: Explanatory Notes: Describe the procedure that indicates how it carries out the identification of commercial partners that require compliance with minimum standards in terms of security. Ensure you include the following points: a) A register of commercial partners that must comply with security requirements, and mention what type of providers these are (transport, storage, custodian service, private security company, correspondent agencies, loading and unloading service for merchandise, etc.). b) Indicate in what documentary form (agreements, accords, contractual clauses and/or addenda) it ensures that its commercial partners comply with security requirements. c) Indicate if there are agreements, accords, contractual clauses and/or addenda, regarding the implementation of security measures with its service providers inside the installation, such as: private security, cafeteria, gardening, cleaning and maintenance services, IT providers, etc. d) Indicate if it has commercial partners to whom membership in a supply chain security program is required (for example: CTPAT or any other Authorized Economic Operator Program of the WCO) as well as the information and documentation requested of them.
Indicate the total annual number of customs declarations and the global value of those carried out by each of the installations from which it transmits the validation of the declarations in each of the authorized customs offices of the customs patent. In the case of partnerships with other customs brokers, there must be a list of the clients of the certified Customs Broker that are managed by said partnership. Indicate the total annual number of customs declarations and the global value of those managed by each of the partnerships with other customs brokers to which it belongs and indicate the following: a) Name and denomination of the partnership. b) Customs offices through which the partnership operates. c) Complete address of the installation(s). Describe how it ensures that the partnerships it has with other customs brokers and in which its patent is not an attachment or additional one comply with the minimum requirements in terms of security.
4.3 Commercial partner reviews. The Customs Broker through the Security Committee must carry out periodic security evaluations (as well as derived from risk situations), of the processes and installations of business associates based on a risk analysis, to guarantee that they have minimum standards in terms of security required by the Customs Broker based on the Authorized Economic Operator Program, keep records of them, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the Customs Broker must communicate them to its partner and/or supplier and provide a justified period established in a procedure to address the observations or areas of opportunity identified, or in case, have the necessary measures to sanction it. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of said reviews or security evaluations prioritizing partners that are more critical according to its risk analysis. If a member is not evaluated and the Customs Broker does not know if the processes and installations of its commercial partners function correctly, it puts its supply chain at risk. Response: Explanatory Notes: Describe the procedure to carry out evaluations for the verification of security requirements (processes and installations) of its commercial partners, ensure you include the following points: a) Periodicity with which it carries out visits to the commercial partner (these must be at least once a year and derived from risk situations). b) Program or calendar for the execution of security reviews. c) Record or report of the verification and in case of the corresponding follow-up.
d) The verification format(s) must be properly filled out, placing the date, name, and position of those participating in the review, signatures, etc. e) Indicate what action measures are taken in case commercial partners do not comply with the established security requirements. f) In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the periodicity with which its status is reviewed, how it registers it, and the actions it takes in case it is detected that it is suspended and/or cancelled according to what is established in its procedure. For partners that have said security certification (granted by an authority), it will not be necessary to carry out visits, as long as the status of the certification is valid according to what is established in its procedure. The procedure must include: a) Points of review in terms of security. b) Preparation of reports. c) Feedback and agreements with the commercial partner. d) Follow-up to agreements. e) Measures in case of detection of non-compliance with requirements. f) Record of evaluations. g) Area or person responsible for carrying out this procedure.
5.1 Process mapping. There must be a process map that describes step by step the flow of information and operational for the transfer of foreign trade merchandise throughout the supply chain, allowing having a broad vision of its operations in terms of foreign trade. The Customs Broker must take into account and include within its mapping all parties involved in its supply chain, containing those that handle import and export documentation, others that may not handle the cargo directly, but may have operational control such as transporters (long distance, crossing or transfer, subcontracted, etc.), storage, sub-maquila, national and foreign suppliers, direct and indirect, etc. If within its supply chain any part of the transport is subcontracted, it is indispensable that it be considered within its risk analysis and its process mapping, since, the more direct and indirect suppliers, the greater the risk involved.
Response: Explanatory Notes: Attach the document where the mapping of processes through which the flow of information and import and export merchandise passes is illustrated and described, from the point where it receives it until its delivery, with the purpose of having well identified each of the steps that involve the reception, the dispatch of the merchandise until its delivery at the final destination. This process mapping must contain at least the following aspects:
Verification of the corresponding registry.
Granted mandate.
Revalidation of the transport document in case.
Prior review before dispatch.
Tariff classification.
Capture of the customs declaration.
Compliance with regulations and non-tariff restrictions (obligation to have permits from the competent authority before presenting the merchandise for dispatch).
Generation of the COVE (in case).
Value declaration.
Determination of contributions.
Review of information transmitted to the SEA with the documentation generated from the shipment (Gloss).
Payment of contributions.
Payment of maneuvers.
Validation of the customs declaration.
Presentation of merchandise before the automated selection mechanism.
Free customs clearance.
Customs Recognition.
Procedure in case of sample taking (The importer may provide them through its Customs Broker at the time of dispatch as long as the samples contain the precints, seals, or any means that manifest that the laboratory result is preserved sterile or it can be done by the authority).
Handling and control of security means, high-security padlocks/seals, and others.
Verification of the delivery of the merchandise at the agreed destination in case.
Procedure for re-dispatch of merchandise.
Procedure for the promotion of withdrawal of an import or export.
Subdivision of the shipment.
Effective communication to customs authorities for cases that represent a risk in terms of security.
Account of expenses of the shipment.
Measurement for customer satisfaction.
Treatment for complaints.
Verification of merchandise in transport.
Consolidation of the shipment.
Formation of the electronic file of each of the customs declarations or customs documents (Article 167 of the Law).
5.2 Delivery, receipt, and discrepancies in the cargo. The Customs Broker must supervise, according to the type of operations it carries out and based on its risk analysis, the loading or unloading of the shipment verifying the detailed description of the merchandise, weight, labels, marks, quantities, and other data that help to quantify and fully identify the merchandise by comparing said information with the corresponding invoices, bill of lading, air waybill, or packing list. Considering and derived from these reviews, the documented procedure(s) to detect and report missing, surplus, prohibited merchandise, or any other discrepancy in the delivery or receipt of the merchandise, which must be investigated and resolved. Likewise, the driver transporting the merchandise must be delivered the required documentary information for its correct transfer (for example: customs declaration, packing list, invoice, contact data, and/or procedure in case of any security incident or inspection by any authority, among others). Response: Explanatory Notes: Attach the documented procedure in which it indicates step by step how the delivery and receipt of the cargo is carried out, indicating how it controls or what security measures it has implemented to mitigate the risk of collusion or complicity between employees, such as the driver and personnel from the dispatch areas (in case), warehouse, security guards, etc. Attach the documented procedure to detect and report discrepancies in the delivery or receipt of the merchandise and ensure it includes the following points: a) Responsible for carrying out the review. b) Documents to compare. c) Areas to which the information is reported. This procedure must be applied to the merchandise that is received from import, export; and in case of applying, in the review at intermediate points.
5.3 Processing of information and cargo documentation. The Customs Broker must have documented procedures to ensure that the electronic and/or documentary information sent by their clients from their service request, during the movement and clearance of goods, as well as the information received from business associates, is legible, complete, accurate, reported in a timely manner, and protected against changes, loss, or introduction of erroneous information. The Customs Broker must have access to the information of each cargo clearance they perform, in a secure and accessible manner, in written or electronic form. Likewise, the forms and documentation related to the clearance should be secured to prevent unauthorized use. Response: Explanatory Notes: Attach the documented procedure for the processing of information and cargo documentation. Briefly explain what it consists of. a) Detail how you receive and transmit relevant information and documentation regarding the transfer of foreign trade goods with your commercial partners (indicate if you use a specific computer control system and briefly explain its function). Also, detail how you ensure that the information provided is legible, complete, accurate, reported in a timely manner, and protected against changes, loss, or introduction of erroneous information. b) The electronic information of shipments and cargo in general must include the seal and/or lock number with which the cargo was secured and, where applicable, changes due to review by any authority. c) Indicate how business associates transmit information to the Customs Broker, and how they ensure its protection.
5.4 Inventory Management, Control of Packaging, Container, and Crating Materials. Where applicable, documented procedures must be in place for inventory control and storage of cargo, and periodic reviews must be carried out to verify their correct management (for example, in the case of invoice subdivision or shipping documents, etc.). Likewise, where applicable, you must have a documented procedure for the control and supervision of packaging and crating materials for goods (for example, in goods labeling processes), which also includes the procedure for control, dissemination, and prevention of visible pest contamination, in the case of using wooden packaging materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack, move, and protect cargo throughout its entire supply chain. Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, among other aspects according to your operation: a) The frequency with which you carry out stock verification (periodic inventory). Indicate if there is a documented scheduled calendar to perform them. b) Indicate what is done in the case of surpluses and shortages in inventories. c) Indicate the treatment given to the control and handling of packaging, container, and crating materials, which must also include the procedure for control, dissemination, and prevention of visible pest contamination, in the case of using wooden packaging materials (such as pallets, boxes, crates, cages, reels, dunnage, chocks, supports, or platforms) to stack, move, and protect cargo. d) This point is also focused on reducing the risk of introduction or dissemination of quarantine pests of importance to the country through packaging (imports); therefore, describe how you comply with the provisions established by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144 SEMARNAT-2017, in accordance with International Standard for Phytosanitary Measures No. 15, titled Regulation for Wood Packaging Material Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. Regarding waste or leftover packaging and crating material, indicate the procedure carried out for its handling and/or destruction. The applicant's procedures may include: a) Warehouse accessible only to authorized personnel. b) Frequency of stock control. c) Control of incoming goods, transfers to other warehouses, consolidation or deconsolidation. d) Actions taken if irregularities, discrepancies, losses, or thefts are identified. e) Treatment of deterioration or destruction of goods. f) Separation of various types of goods, for example, high-value or hazardous goods.
5.5 Internal Communication. The Customs Broker must have communication devices and/or systems in order to have immediate contact with the personnel of the different areas responsible for carrying out the customs clearance of goods. Additionally, a backup system must be available and its proper functioning verified periodically. Response: Explanatory Notes: Describe in detail how the Customs Broker communicates with the personnel responsible for carrying out the clearance of goods, mainly with those who have direct contact with the goods and with the means of transport (agents, dependents, classifiers, etc.), in the event of any security incident. Indicate if operational and administrative personnel have or have access to devices (radios, mobile phones, landline telephones, etc.) to communicate with each other and/or with the relevant parties. These must be accessible to users to enable a prompt response. Describe the procedure for the control and maintenance of communication devices; ensure you include the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate if you have backup communication devices in case the permanent system fails, and briefly describe them. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Record of verification and maintenance of devices. c) Method of assignment of communication devices.
6.1 Management of Customs Clearance. The Customs Broker must have documented procedures that detail each of the steps shown in their process mapping established in sub-standard 5.1. Response: Explanatory Notes: Attach the documented procedures that describe each of the points or steps contemplated in your process mapping (5.1). These procedures must include the following points: a) Persons responsible for each procedure. b) Formats and documents used. c) Systems used. d) Supply chain actor with whom information is exchanged. The review of these procedures that detail the operation of the customs clearance of goods must at all times coincide with the information and/or documentation provided by the client. Mainly on the following topics: a) Tariff classification (supporting information or technical sheets of the goods that the client sends to the Customs Broker for correct classification). b) Compliance with regulations and non-tariff restrictions. [Interaction with clients and different government departments for compliance with regulations and non-tariff restrictions (RRNA)]. c) Value declaration (The verification and confirmation of the information provided by the client will serve as support for the use of the valuation methods established in the Law). d) Payment of contributions (the exchange of information generated for the payment of contributions must be clear and precise with the client).
6.2 Control in Fiscal Premises. The Customs Broker must have documented procedures that contemplate the control of official badges requested for personnel entering fiscal premises, such as: customs agent, dependent, etc. Likewise, one of the customs obligations is the evaluation and certification of the customs agent figure; therefore, the Customs Broker must have a documented procedure to comply with what is established in the Law. Response: Explanatory Notes: Attach the documented procedure that describes the control of official badges for personnel entering fiscal premises; ensure you include the following points: a) Procedure for requesting badges with Associations or Confederations. b) Badge use policies. c) Infractions related to the improper use of badges. d) Fines applicable to infractions related to the improper use of badges. An updated list of requested badges, as well as those that have been canceled, must be maintained. Describe the process that the customs agent must follow to apply evaluations and keep their certifications of activities current, such as: a) Supervision of previous and derived acts of customs clearance. b) Preparation of the customs declaration (pedimento). c) The set of acts and formalities related to the entry of goods into the national territory and their exit from it. The Customs Broker must have the corresponding evidence supporting the evaluations and certifications of the aforementioned topics.
7.1 Use of Seals and/or Locks on Containers and Trailers. The Customs Broker must have, where applicable, a documented procedure, where means of transport, containers, trailers, and/or semi-trailers and high-security seals used in the international logistics chain are identified, indicating how their integrity is maintained. For this reason, as one of the security mechanisms, the Customs Broker, where applicable, must use locks or high-security seals that meet or exceed Standard ISO 17712 on all containers and loaded trailers that are subject to foreign trade and maintain their integrity until clearance. For this, the Customs Broker must have documented procedures to correctly place high-security seals and verify their integrity. The procedures must include the steps to follow if a seal is found to be altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to business associates involved in the supply chain, and the investigation of the security incident; these must be reported to security personnel, business associates who may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program. Likewise, in said procedure, it is necessary for the Customs Broker to include what is related to the administration of high-security seals, which must include, control, assignment, safeguarding, handling of discrepancies, and destruction of seals and locks (the latter is mandatory whenever seals are broken in their facilities). Regarding the provider of the seals and/or locks, it must be demonstrated how these comply with Standard ISO 17712. The Customs Broker or a security supervisor must carry out periodic and documented audits of the high-security seals and/or locks; these reviews must include the verification of the inventory of stored seals and/or locks and the comparison with inventory records and shipping documents. Also, the Customs Broker must periodically verify the seal numbers used in means of transport and Instruments of International Traffic to corroborate that the information is correct. In the case of having a yard for storing cargo vehicles at the Customs Broker's facilities, empty containers must be secured with a lock and/or indicative seal, or in a secure area that is guarded and monitored by alarm systems and closed-circuit television and video surveillance. When it is necessary to store (overnight) any loaded container, trailer, and/or semi-trailer, it must be located in a secure area and monitored by alarm systems and closed-circuit television and video surveillance to prevent access and manipulation, and must be closed with a high-security lock. Response: Explanatory Notes: Indicate if the Customs Broker has its own or third-party transport units, containers, and/or trailers. Attach the documented procedure for the placement and review of seals and/or locks on vehicles, means of transport, containers, rail cars, trailers, and/or semi-trailers. This must include, among other aspects according to your operation: a) Verify that the seal or lock is intact and determine if there is evidence of improper manipulation. Use the VVTT inspection method:
b) Review and compare the documentation containing the number of the original seal or lock and, where applicable, any additional ones carried during the transfer of goods. In case of using a replacement seal and/or lock, that number must be registered within the Customs Broker's control. If altered seals and/or locks are identified, they must be kept to help carry out the investigation of said incident or discrepancy and, as appropriate, report the compromised seals and/or locks to the foreign authority. c) Review that closing devices, hinges, and pins are attached to the trailer or container and welded or riveted. Protective plates can also be placed on door hinges and/or a seal/adhesive tape placed on at least one side. Likewise, the correct functioning of handles, latches, and all other locking or closing mechanisms of cargo vehicles must be verified to detect manipulations and any inconsistencies before placing any sealing device. d) Indicate how high-security locks are assigned and replaced in the case that, during the route, it is inspected by another authority. If a seal and/or lock breaks in transit, the cargo must be examined, the replacement seal and/or lock number must be registered, and the driver must immediately notify business associates when this happens, indicate who broke it, and provide the new seal number. Where applicable, attach the documented procedure for the control and handling of seals and/or locks. This must include, among other aspects according to your operation: a) Inventory of locks and/or seals. b) Who has access and how locks and/or seals are safeguarded. The management of seals and/or locks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (record of seals used, as well as the receipt of new seals and/or locks).
c) Describe how the Customs Broker participates in audits of high-security seals and/or locks, the reviews they perform, the records they generate, and the actions they take if discrepancies are identified. Also, how dependents verify seal numbers used in means of transport and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). d) How discrepancies in seal and/or lock numbers are addressed. e) Record of seals and/or locks used at the time of customs recognition. In the case of lost or stolen seals and/or locks, describe the procedure followed by the Customs Broker. Indicate who the provider(s) are and how they prove that the specifications of the seals and/or locks comply with Standard ISO 17712 (attach certificate of conformity, issued by the certifying company responsible for verifying compliance with the corresponding ISO). In the case of having a yard for storing cargo vehicles at the Customs Broker's facilities, describe how you ensure the integrity of means of transport is cared for. All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of Means of Transport, Containers, Trailers, and Semi-trailers. In the case of having a yard for storing means of transport, the Customs Broker must have established procedures to verify the physical integrity of the structure of the means of transport, container, trailers, and/or semi-trailer used as Instruments of International Traffic, even the reliability of the door lock mechanisms, with the purpose of identifying natural or hidden compartments. Inspections of means of transport or cargo vehicles, containers, and trailers (land cargo) must be systematic and have records of these inspections, in an access-controlled area and carried out in a place monitored by alarm systems and closed-circuit television and video surveillance; said system must cover the inspection process in its entirety. The documented procedure for its inspection must include, by way of example and not limitation, the following review points: Means of Transport Trailers, Rail Cars, Semi-trailers, and Containers
Furthermore, the security and agricultural inspection format must include the following information: a) Inspection date; b) Inspection time; c) Vehicle license plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected; and f) Name of the employee performing the inspection and the supervisor. The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and become part of the import and export documentation. The documentation must be kept for one year for investigation in the event of any security incident, as well as to demonstrate continuous compliance with these inspection requirements. Indicate whether the repair or maintenance of transport units, containers, or trailers is performed in the same facilities or carried out with an external provider.
8.1 Employment Background Verification. The Customs Agent must have documented procedures to investigate and verify the information stated in the curriculum vitae, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either independently or through an external company. Similarly, for positions that, due to their sensitivity, require it and affect the security of shipments subject to foreign trade, in accordance with their previously conducted risk analysis, they must consider requesting stricter requirements for hiring and during their employment tenure, which must be carried out periodically at least once a year. Regarding personnel already working in the company, periodic investigations must be conducted based on the activities and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for personnel hiring and ensure you include the following: a) Requirements and documentation demanded. b) Tests and exams requested. c) Indicate the critical areas and/or positions identified as risky, according to your analysis. d) Indicate what the additional requirements are for specific areas and/or job positions, such as criminal records (if company legislation and policies allow), non-criminal record certificate, socioeconomic studies, clinical studies, toxicological (drug use) studies, etcetera. If applicable, indicate the job positions or areas where they are required and with what frequency they are carried out. e) Indicate whether, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. f) In the event of hiring through a staffing agency, indicate whether it has documented procedures for personnel hiring and how it ensures they comply with the same. Briefly explain what they consist of. The procedures for personnel hiring and contractors may include: a) Thorough investigations of the work and personal backgrounds of new employees. b) Confidentiality and liability clauses in employee contracts. c) Specific requirements for critical positions. d) If applicable, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. The Customs Agent may consider the results of background checks on candidates, as permitted by current legislation, to make hiring decisions. Background checks are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel Termination Procedure. There must be documented procedures for personnel termination, which include the handover of identification, and any other items provided to them to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etcetera). Likewise, this procedure must include termination in those systems, both computer and access, among others that may exist. Response: Explanatory Notes: Describe the procedure for personnel termination, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the handover of identification, uniforms, keys, and other equipment is performed and confirmed. c) Indicate the control, record, and/or format, in which the handover of material is identified and ensured, and termination in computer systems (if applicable, attach). d) Indicate the type of records of personnel who ended their labor relationship with the Customs Agent, so that in case it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel Administration. The Customs Agent must maintain an updated system, control, or database of active employees. Likewise, it must carry out and maintain updated records of affiliation to social security institutions and other legal labor records. In the event that the Customs Agent has personnel hired by its business partners and working within the facilities, it must ensure that they comply with the requirements established for the rest of its employees. Response: Explanatory Notes: Indicate whether the Customs Agent has an updated system, control, or database, both for personnel hired directly, as well as that hired through a service provider company, and ensure it includes, by way of example but not limitation, the following points: a) Full name. b) Updated photograph at least every five years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etcetera). d) Family ties. e) Work background. f) Diseases. g) Medical exams. h) Training. i) Psychometric exams. j) Toxicological exams. k) Results of periodic evaluations. l) Observations. This personnel must be hired in accordance with current labor laws and regulations.
9.1 Document Classification and Handling. Procedures must exist to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified, and procedures for its destruction must be established in accordance with the corresponding legislation. The Customs Agent must conduct reviews regularly to verify access to information and ensure that it is not used improperly. Some of the sensitive information referred to in the previous paragraph, depending on the case, may be: a) Compilation of documentation prior to customs clearance. b) Export/import declaration. c) Packing list. d) Bill of lading (air waybill, bill of lading, and waybill) as applicable. e) Copy of documents proving compliance with non-tariff restrictions and regulations on imports issued in accordance with the corresponding laws. f) The document on the basis of which the provenance and origin of the goods are determined for the application of tariff preferences. g) The document in which the guarantee granted through a deposit made in the guarantee customs account referred to in Article 84-A of the Law is recorded, when the declared value is lower than the estimated price established by the SE. h) The weight or volume certificate issued by the certifying company authorized by the Secretariat through rules, regarding the clearance of bulk goods in maritime traffic customs, in the cases established by the Regulation. i) The information that allows identification, analysis, and control as indicated by the Secretariat through rules. j) Manifestation of the value of the goods. k) Calculation sheet for the determination of contributions, benefits, and/or accessories. l) Responsive letter (technical and MSDS safety data sheet for materials, if applicable). m) Insurance policy for the cleared goods. n) The Customs Agent must conduct reviews regularly to verify access to information and ensure that it is not used improperly.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: a) Control register for delivery, loan, among other documents. b) Restricted access to the archive area. c) Storage and classification policies. d) An updated security plan describing the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss thereof. e) In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, the Customs Agent must have sufficient protection to preserve the confidentiality, integrity, availability, and auditability of the information generated as a result of the foreign trade operations it carries out with authorities, its clients, and other actors. Likewise, it must promote security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etcetera), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the Customs Agent must have established information technology policies, procedures, and standards that must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etcetera). Customs agents that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote user access. For the above, there must be written procedures and infrastructure to protect the Customs Agent against loss, theft, leakage, hacking, and/or ransomware of information, this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology Systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Sensitive information must be protected through these information security policies, in addition to having backup copies. Access to Information Technology Systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access. If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how it backs up and ensures the security of its information, in addition to protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which information backups are carried out. b) Who has access to them and who authorizes the recovery of information. c) Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. d) Mention whether, to carry out this type of tests or vulnerability scans, it does so through software, a third party or provider, and if so, indicate the name or corporate name. e) In the event of finding vulnerabilities, describe the corrective actions that must be implemented. f) Indicate whether it shares information about cybersecurity threats with its business partners participating within its supply chain (for example: communications, bulletins, emails, etcetera). g) Systems must be protected under passwords and frequently modified; therefore, indicate the procedure for changing them. h) Indicate if there are information security policies for their protection. i) There must be a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to its systems and/or Information Technology data (any system used by the company), as well as the abuse of the policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors.
j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in the event of the detection of any violation of the Information Technology systems and security policies. The Information Technology and cybersecurity policies and procedures must be reviewed annually and updated as a result of an attack or according to situations that may put the Customs Agent's systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In the event of allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely. k) Indicate if business partners have access to the Customs Agent's computer systems. If so, indicate what programs they use and how they ensure control of access to them. l) Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the Customs Agent's information backup must also include at least the following: a) How and for how long the data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in case of incident and how to recover the information. c) Frequency and location of backup copies and archived information. d) If backup copies are stored in sites alternative to the facilities where the data processing center is located. e) Tests of the validity of data recovery from backup copies.
The procedures regarding the protection of the Customs Agent's information must also include: a) An updated and documented policy for the protection of the Customs Agent's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or ciphered format. b) Detail if it operates with multiple systems (sites/locations) and how such systems are controlled. c) Who is responsible for the protection of the Customs Agent's computer system (responsibility should not be limited to one person but to several so that each can control the actions of the rest). d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to personnel authorized to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements. e) Indicate the elements or format that passwords must have, for access to Information Technology systems and equipment methods of authentication, and who provides those passwords. f) Indicate the name of the firewall and anti-virus used (include licensing-related information), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses (software and hardware).
All computer equipment, electronic media (hard drives, cell phones, etc.) and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed adequately to prevent information leakage.
g) In the event of staff turnover, access to computer, telecommunications, and network equipment must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc.
h) Measures planned to handle security incidents in case the system is compromised.
Administrative and operational employees must know the procedures established by the Customs Agent to consider a risk situation and know how to report it.
Specific training must be provided to employees who, due to their functions, are in direct contact with goods and/or transport means, as well as to employees who are in critical and/or sensitive areas determined under their risk analysis (security areas, shipments and receipts, if applicable, as well as those who receive and open mail and packages, among others).
10.1 Training and awareness on threats. The Customs Agent must have a training and awareness program on supply chain security policies, directed to all its employees (operational and administrative), and additionally make available informational material regarding the procedures established by the Customs Agent to consider a situation that threatens its security and know how to report it.
These training programs must foster the active participation of employees in security controls and mechanisms; the Customs Agent must ensure that all its employees know, understand, and apply supply chain security policies, as well as keep records of all training efforts provided and the list of those who participated in them.
Likewise, and with the purpose of maintaining the integrity of operations and processes related to the customs clearance of goods, personnel must receive specific training according to their functions. The topics that must be included are the following: maintaining cargo integrity, conducting container, trailer, and/or semi-trailer reviews for agricultural and security purposes (if applicable), receipt and review of mail and packages, prevention of operations with proceeds of illicit origin (money laundering, terrorist financing, etc.), how to recognize and how to report internal conspiracies, protection of access controls, as well as training regarding smuggling, cargo theft, placement of seals, control of high-security seals (VVTT inspection method), prevention of visible contamination by pests, use of official badges, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs.
Update training must be carried out periodically, after a security incident, and when there are changes in the Customs Agent's procedures.
In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train personnel on the Customs Agent's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or information kidnapping), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodically maintain update programs.
Training programs must foster the active participation of employees in security controls and mechanisms, as well as keep records of all training efforts provided by the Customs Agent and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives.
Response: Explanatory Notes: Must have a training program on security and prevention of security incidents in the supply chain for all employees working for the Customs Agent (administrative, operational, direct or indirect). Briefly explain what the training program consists of and ensure to include the following: a) Brief description of the topics taught in the program. b) When they are taught (Onboarding, specific periods, derived from audits, security incidents, etc.). c) Frequency of training, as well as updates and reinforcement. d) Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all objectives of the same. e) Explain how employee participation in security matters is fostered.
Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments; b) Smuggling hidden in natural compartments; c) Signs of pest contamination; and d) Procedures to follow if something is found during an inspection of the transport means or if a security incident occurs during transit.
Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials, in accordance with International Standard for Phytosanitary Measures No. 15 entitled Regulation of Wood Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations and the identification of infested wood.
In the case where the Customs Agent identifies that any foreign trade shipment is involved in a situation that puts the supply chain security at risk, due to suspicion of a business partner or person, they must inform the competent authority, business partners that may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, as well as the competent authority, and, if possible, before the border crossing, exit, or customs clearance (import and export). Procedures must include the steps to follow if a seal is found to be altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to involved business partners in the supply chain, and the investigation of the incident. All the aforementioned procedures must be reviewed periodically or at least once a year to ensure that contact information and action protocols are correct.
11.1 Reporting of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with their logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners that may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of such anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as mechanisms to anonymously report problems related to security; ensure to include the following: a) Who is responsible for reporting security incidents. b) Detail how it determines and identifies with which authority to communicate in different scenarios or presumption of suspicious activities. c) Mention if it keeps a record of the reporting of these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that so require.
This information and documentation generated to carry out the foreign trade operation of the affected goods must be included in a file with the purpose of identifying each of the processes through which that operation went until the point where the incidence was detected and allowing recognition of the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any security incident, and ensure to include the following: a) Person responsible for carrying out the investigation. b) Documentation that integrates the investigation file of the foreign trade operation. The documents to be included in the file derived from the investigation, by way of example and not limitation, may be: a) General information of the shipment, purchase order. b) Transport request; confirmation of transport means; identification of the transport operator (access records, exit, security inspection records, etc.). c) Container Inspection Formats; exit order; delivery records. d) Videos from alarm systems, closed-circuit television, and video surveillance. e) Documentation generated for the carrier (packing list, bill of lading, instruction sheet). f) Documentation generated for business partners (description of goods, proformas, invoices, etc.). g) Documentation generated by business partners (customs declarations, manifests, tracking and inspection reports, videos if applicable, etc.).
E5. Profile of the Land Auto Carrier. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data provided will replace the data provided when requesting authorization.
General Information. The objective of this Profile is to ensure that the land auto carrier implements security practices and processes that ensure its supply chain, mitigating the risk of contamination of its vehicles with illicit products, as well as loss, theft, and/or any other factor that could compromise the security of the supply chain.
Land auto carriers interested in obtaining the authorization referred to in rule 7.1.5. must have documented and verifiable processes.
Likewise, the transport company interested in the aforementioned authorization must integrate the criteria required in this document into the business model or design it has established, seeking during the implementation of security standards the application of an analysis culture that supports decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the company itself.
As an example of the points or topics requested of interested parties during the filling of this document, which require analysis to identify risks affecting the supply chain, and in turn help detect their treatment, are the following: points of origin and destination, routes, facilities, volume of operations, yard security, previous security incidents, interaction with business partners, among others.
Filling Instructions:
You must fill out a Land Auto Transport Profile of the main facility, as well as each of the main facilities where vehicles are used and safeguarded for the transfer of foreign trade goods. In the case of yards and/or branches that are also under the same RFC, a Profile must be developed for each of them, following strictly what is established in sub-standard 7.3. of this document. This information must coincide with what is stated in your Certified Commercial Partner application.
Detail how the company complies with or exceeds what is established in each of the numerals as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Description of the standard 1.1 Sub-standard. Description of the sub-standard Response. Explanatory Notes. Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards; therefore, you must attach the procedures in Spanish. These procedures must be characterized by describing or defining the objective the document pursues, the start and end of the process, measurement indicators, requirements, documents or formats to be used, responsible parties, among others.
In cases where only an explanation of the procedure is required, it must be detailed and placed in the Response field. The field regarding Explanatory Notes is a guide regarding the points that must be included in the Response of each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once this Land Auto Carrier Profile is answered, it must be attached to the Application for inscription in the Certified Commercial Partner registry referred to in the first paragraph of rule 7.1.5., fraction I, subsection b).
For the purpose of verifying what is stated in the previous paragraph, the SAT through the AGACE may conduct an inspection of the facility indicated here, with the exclusive purpose of verifying what is stated in this document.
Any incomplete Land Auto Carrier Profile will not be processed.
Any question relative to the Certified Commercial Partner Application and the Land Auto Carrier Profile should be directed to the contacts appearing on the SAT Portal.
In the case of being authorized as a Certified Commercial Partner, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and derived from these changes or modifications in the information stated and provided in this Land Auto Carrier Profile to the authority are required, in accordance with what is established in rule 7.2.1., fourth paragraph, fractions I, II, and VII.
When derived from the inspection visit, non-compliance related to minimum security standards results, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the indicated non-compliances.
Facility Data. A Land Auto Carrier Profile of the main facility must be filled out, as well as each of the main facilities where vehicles are used and safeguarded for the transfer of foreign trade goods. And in case of yards and/or branches that are also under the same RFC, a Profile must be developed for each of them, as well as strictly following what is established in sub-standard 7.3. of this document. This information must coincide with what is stated in your Certified Commercial Partner application.
Facility Information. Land Auto Carrier Profile Number: from: RFC: Name and/or Business Name: Name and/or Denomination of the Facility Type of Facility: Street: Number and/or exterior letter Number and/or interior letter Neighborhood: Postal Code: Municipality/Delegation: Federal Entity: Age of the Facility (years of operation): Predominant activity (Transfer / Long Distance):
Type of service (General/Specialized Cargo): Average number of monthly shipments (EXP): (Long distance and/or crossing) Average number of monthly shipments (IMP): (Long distance and/or crossing) Total number of employees at this facility: Facility Surface Area (m 2 ): Total number of yards and/or branches (owned and/or subleased) that are enabled and used for the storage of transport means: Certifications in security programs: (Indicate if this facility has a certification from any of the following programs) CTPAT: Yes No Level: Pre-Applicant: Applicant: Certified: Certified/ Validated: CTPAT Account number (Eight digits): Date of last visit at this facility: Authorized Economic Operator from other countries (AEO) Yes No Program: Registry: Other Supply Chain Security Programs Yes No Program: Registry: Certifications: (Indicate if you have certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The carrier company must establish measures to identify, analyze, and mitigate security risks throughout the supply chain, including its facilities. For this reason, it must develop a written procedure in which risks are determined based on its organization's model (e.g., volume, units, yards, routes, potential threats, etc.), which allows it to implement and maintain appropriate security measures. Based on the above, the company must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be carried out at least once a year, so that it allows identifying other risks or threats in the operation that may arise from the result of an incident or that originate from changes in the company's initial conditions, as well as to identify whether the policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the company's Security Committee must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Attach the risk matrix and the documented procedure that you use to identify risks in your daily operations throughout the supply chain and its facilities (yards and/or branches, offices, boarding houses, mechanical workshops, etc.) must include as a minimum the following points: a) Frequency with which this procedure is carried out. b) Which aspects and/or areas of the carrier company are incorporated into the risk analysis. c) Type of service:
Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the risk appreciation and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Identification of risks in its supply chain and its facilities. c) Risk analysis (causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low). d) Risk evaluation (decision-making to determine the risks to be treated and priority for implementing the treatment). e) Risk treatment (application of alternatives to change the probability of risks occurring). f) Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use risk evaluation techniques according to the current international standard ISO 31000, and specifically ISO 31010, where according to its business model they must implement.
1.2 Security Policies. Companies must have a manual of policies oriented to prevent, secure, and recognize threats to the security of the supply chain and company facilities, such as drug trafficking, arms trafficking, human smuggling, prohibited goods, and acts of terrorism. To promote a culture of security, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. Senior officials or executives of the company who must endorse and sign the security policy may include the company president, chief executive officer, general manager, security director, or personnel with equivalent rank with decision-making authority.
Response: Explanatory Notes: State the security policy oriented to prevent, secure, and recognize threats in the supply chain and company facilities focused on guaranteeing the integrity of its resources (units, operators, facilities, yards and/or branches, etc.) as well as to ensure the transport of goods, property of third parties or own, and indicate who is responsible for its review, signature, and dissemination to employees, as well as the frequency with which its update is carried out.
This policy must be communicated to employees through a dissemination program and/or campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits, at least once a year, that allow evaluating all processes regarding security in the supply chain in a more critical and profound way, as well as guaranteeing that its employees follow the company's security procedures. Audits must be carried out by the company's Security Committee and a documented procedure must be established, as well as a program or calendar for their execution. Although it is necessary that the audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, risk level, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the follow-up and closure of preventive, corrective, and improvement actions identified. The senior management of the organization must review the results of the audits and undertake the required corrective or preventive actions. The audit process must guarantee that the necessary information is collected to allow management to make this evaluation. The review must be documented, in addition to the fact that the company's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain; ensure you include the following points: a) Indicate how the company carries out the scheduling or calendarization to perform an internal audit, regarding security, in the supply chain. b) Indicate who participates in them, and the records that are made of them, as well as the frequency with which they are carried out. c) Indicate how the company's Management verifies the results of security audits, how it carries out and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure of the same. d) The formats used during internal audits must be properly filled out, and through them, evidence that the security procedures and measures are being put into practice.
1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity, in the event of a situation that affects the normal development of the carrier company's activities and operations. A crisis or contingency may include the interruption of the transmission and exchange of commercial data due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a customs closure, a bomb threat, the detection of suspicious packages, a power outage, the theft and/or damage of goods, threats or extortion, blockades or road closures, and when the operator identifies that they are being watched or followed during the transport of goods, among others. Such plans must be communicated to personnel through periodic training, as well as carrying out tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness, from which a properly filled-out and signed record must be maintained (for example: result reports, minutes, or reports, which must be backed up by video recordings, photographs, etc., that demonstrate their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in the event of an emergency or security situation that affects the normal development of the company's foreign trade activities. This procedure must include, by way of example and not limitation, the following: a) What situations it contemplates, describing the action plan and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. b) What mechanisms it uses to disseminate and ensure that these plans are effective. c) Contemplate the scheduling and carrying out of tests, practical exercises, and annual drills and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution). In the case of carrier companies of Hazardous Materials and Waste, an emergency sheet must be attached indicating the actions to be taken in case of incident or accident (leaks, spills, explosions, fires, etc.).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity has been detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal routes, and the location of buildings must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the facilities are constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others) and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out inspection, maintenance, and repair tasks of the facilities. Explain how the review and maintenance of the integrity of the structures is carried out. Attach a general distribution or architectural plan, where limits, access routes, the location of offices, parking lots, critical areas, adjacent yards and/or boarding houses can be identified.
2.2 Access at Gates and Booths. The entrance or exit doors of vehicles and/or personnel accessing the yards and/or vehicle boarding houses for cargo vehicles and administrative offices must be attended and/or supervised either by own personnel or by security personnel. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each, and indicate how they are monitored (In case of having assigned personnel, indicate the quantity). Detail if there are blocked and/or permanently closed doors and/or accesses. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the company's perimeters, based on a risk analysis. The area of the yards and/or boarding houses must be delimited for cargo vehicles (tractors), trailers, and/or semi-trailers and/or containers as appropriate. These must be inspected regularly and keep a record of the review with the purpose of ensuring their integrity and identifying damage, which must be repaired as soon as possible by the personnel designated for these tasks. In the case of providing merchandise storage services, this zone must be clearly delimited, identified, and monitored according to the service required (national or international, as well as high value and dangerous) to prevent unauthorized entry.
Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls that the company has; ensure you include the following points: a) Indicate the characteristics of the same (material, dimensions, etc.). b) In case of not having fences, justify the reason in detail. c) Frequency with which the integrity of the perimeter fences is verified, and the records that are kept with the purpose of ensuring their integrity and identifying damage, which must be repaired as soon as possible. d) Indicate the personnel or area responsible for carrying out inspection and damage repair tasks. e) Indicate how your yards are divided (briefly describe, how they separate tractors, containers, trailers, and/or semi-trailers with domestic and/or international cargo, empty, under repair and/or maintenance; cargo vehicles; workshops; offices; among others). The procedure for the inspection of perimeter fences could include: a) Personnel responsible for carrying out the process. b) How and how often the inspections of the fences, perimeter fences, and/or peripheral barriers and buildings are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that repairs and/or modifications meet the technical specifications and necessary security requirements.
2.4 Parking Lots. Access to the parking lots of the facilities must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the areas for handling and storage of means of transport, containers, trailers, and semi-trailers, as well as in adjacent areas.
Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots; ensure you include the following points: a) Persons responsible for controlling and monitoring access to parking lots. b) Identification of parking lots (specify if employee and visitor parking is separated from means of transport, containers, trailers, semi-trailers, and merchandise handling). c) How entry and exit control of vehicles to the facilities is carried out. Indicate the records that are made for parking control and the existing control mechanisms (for example: badges, card readers, lanyards, etc.), how they are assigned, and the responsible area for doing so. d) Policies or mechanisms to not allow the entry of private vehicles to the areas for storage of means of transport and, where applicable, merchandise handling.
2.5 Key and Lock Device Control. According to the risk analysis, windows, doors, and inner and outer fences must be secured with locking devices. The carrier company must have documented procedures for the handling, safeguarding, assignment, and control of the keys to the facilities, to the inner areas that have been considered critical, and to the cargo vehicles, designating those responsible for the administration, control, and registration of these. Likewise, a record must be kept and signed responsibility letters must be established for persons who, based on their functions, have keys or authorized access.
Response: Explanatory Notes: Indicate if all doors, windows, inner and outer entrances have locking or security mechanisms. Attach the documented procedure or procedures for the control, safeguarding, assignment, and handling of keys for means of transport and for facilities, offices, and inner areas. Ensure that these procedures include the following points: a) Persons responsible for administering and controlling key security. b) Format and/or control record for key lending. c) Treatment of loss or non-return of keys. d) Indicate if there are areas where access is gained with electronic devices and/or some other access mechanism. In case of using padlocks that are placed on containers, trailers, and/or semi-trailers within the facilities, describe in detail the criteria for the handling, control, and safeguarding of the keys for said padlocks.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of people, material, and/or equipment located there, including the following areas: entrances, exits, parking or storage areas for tractors, trailers, rolling equipment, perimeter fences and/or peripheral barriers, inner fences, loading, unloading, handling, and storage of merchandise (in case of providing this service). An emergency and/or backup system must be available in sensitive areas.
Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: a) Indicate which areas are illuminated and which have a backup system (Indicate if you have an auxiliary power plant or some other mechanism to supply electricity in case of any contingency). b) How you ensure that the lighting system is appropriate in each of the company's areas, in such a way that it allows clear identification of the personnel, material, and/or equipment it covers. c) Person responsible for the control and maintenance of lighting systems. d) Maintenance and review program (in case it coincides with another process, indicate it). The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting.
2.7 Communication Devices. The carrier company must have devices and/or communication systems with the purpose of having immediate contact with security personnel and/or emergency and security authorities in case they are required. Additionally, a backup communication system must be available and its proper functioning must be verified periodically.
Response: Explanatory Notes: Describe the procedure that personnel must carry out to contact security personnel or, in their case, the corresponding authority in case of any incident. Indicate if operational and administrative personnel have or have access to devices (landlines, mobile phones, alert and/or emergency buttons), to communicate with security personnel and/or whoever corresponds (these must be accessible to users, to be able to have a prompt reaction). Indicate what communication devices the security personnel of the carrier company uses (landlines, cell phones, radios, alarm system, etc.).
Describe the procedure for the control and maintenance of communication devices, ensuring you include the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate whether you have backup communication devices in case the permanent system fails, and if so, briefly detail them. d) Indicate whether the company's operators/drivers use telephones, radios, cell phones, citizen band (CB), or any other means for internal communication and the policies for assigning them. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Record of verification and maintenance of the devices. c) Method of assignment of communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance. Alarm systems, closed-circuit television, video surveillance, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in facilities and other considered sensitive areas, notify the corresponding area, and also be used as evidence in investigations derived from any incident. These systems and security technologies must be installed according to a prior risk analysis, such that areas involving the access of personnel, visitors, suppliers, loading/unloading, cargo and passenger vehicles, and other considered sensitive areas are kept under surveillance and monitoring; likewise, areas where vehicles and containers are normally located (parking lots, storage where they stay overnight) and, if applicable, where merchandise is stored (if this service is provided). Such systems must allow clear identification of the area or environment being monitored, be permanently recording, and maintain a backup of recordings for at least one month, considering that, if your logistical processes exceed this period, the retention period for these backups must be increased, in order to have the necessary elements to assign corresponding responsibilities in case of a security incident. Alarm systems, closed-circuit television, video surveillance, and security technologies must have a documented operating procedure that includes supervision of the equipment's good condition and verification of the correct position of cameras, indicating the frequency with which recordings must be backed up, as well as those responsible for their operation. This system and all security technology infrastructure must have restricted access.
Response: Explanatory Notes: Mention the documented procedure indicating the functioning of the external alarm central system or sensors, and if applicable, describe the following points: a) Indicate whether doors and windows have alarm sensors or motion sensors. b) Procedure to follow in case an alarm is activated.
Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensuring you include the following points: a) Indicate the number of cameras in the installed alarm, closed-circuit television, and video surveillance systems, their technical characteristics, and their location (detail if they cover entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as the storage location of vehicles). b) Point out the location of alarm, closed-circuit television, and video surveillance systems and security technologies, where monitors are located, who reviews them, as well as operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Perform periodic and random reviews of recordings. Indicate how they are reviewed (random, weekly, special events, restricted areas, etc.), who the designated personnel are, and whether management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept (must be at least one month). e) Alarm, closed-circuit television, and video surveillance systems and security technologies must have an alternative power source that allows them to continue functioning in case of an unexpected loss of direct power. Therefore, indicate whether alarm, closed-circuit television, and video surveillance systems and security technologies are backed up by an electrical power plant or some other mechanism to supply electricity, which guarantees their functioning. These systems should have an alarm/notification function, indicating a failure condition in operation and/or recording; indicate if your systems have this function. f) Indicate if, in addition to alarm, closed-circuit television, and video surveillance systems, you use any other type of technology to strengthen the security measures you already have. g) Describe the procedure implemented to regularly test and inspect alarm, closed-circuit television, and video surveillance systems and security technologies and ensure their proper functioning. The results of inspections and functional tests must be documented, as well as necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. h) Indicate if the alarm provider and alarm, closed-circuit television, and video surveillance system provider has access to security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security personnel. The transport company must have security and surveillance personnel. This personnel plays an important role in the physical protection of facilities, yards and/or parking lots where cargo vehicles (tractors), trailers, and containers are stored, as well as for controlling the access of all persons to the property. Security personnel must have a documented procedure to carry out their functions, and have full knowledge of mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the facilities. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel, ensuring you include the following points: a) Indicate the number of security personnel working in the company. b) Point out the positions and/or functions of the personnel, and operating hours. c) In case of hiring an external service, specify the number of personnel employed, operational details, records, reports, etc. d) In case of having armed personnel; describe the procedure for the control and custody of weapons.
3.2 Identification of employees, visitors, and suppliers. There must be an identification system for employees, visitors, and suppliers for the purpose of accessing facilities. Employees should only have access to those areas they need to perform their functions. Visitors and suppliers must present an official photo ID upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification and be accompanied by company personnel during their stay in the facilities, ensuring that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented. Management or the company's security personnel must properly control the delivery and return of identification badges for employees, visitors, and suppliers and ensure that they always wear the provided identification in a visible place. This procedure must be documented, as well as procedures for the delivery, return, and change of access devices (for example, keys, proximity cards, etc.). Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Attach the documented procedure for the control of identifications. Describe the procedure for the identification of employees, ensuring you include the following points: a) Identification mechanisms (photo ID, uniform, etc.). b) Indicate whether employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable). c) Indicate how personnel hired by a business partner, working within the facilities (contractors, subcontractors, etc.) are identified. The procedure must also describe how the company delivers, changes, and withdraws employee identifications and access controls, ensuring you include the areas responsible for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Describe the procedure for the access control of visitors and suppliers, ensuring you include the following points: a) Point out what records are kept (Personal forms for each visit, logbooks). b) The record of visitors and suppliers must include the following:
3.3 Procedure for identification and removal of unauthorized persons or vehicles. The company must have documented procedures specifying how to identify, confront, or report unauthorized or identified persons and/or vehicles.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: a) Responsible personnel. b) Designate a person or area responsible for being informed of incidents. c) Instructions for confronting and directing unidentified personnel. d) Indicate in which cases the corresponding authorities must be notified. e) How the recording of incidents and measures adopted in each case is carried out.
3.4 Courier and package deliveries. Courier and packages intended for company personnel must be examined upon arrival and before being distributed to the corresponding area. Likewise, the transport company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages, ensuring you include the following: a) Personnel in charge of carrying out the procedure. b) Indicate how the personnel or provider of the courier and package service is identified (indicate if an additional procedure to the supplier access procedure is required). c) Point out how packages are reviewed and/or what mechanism is used, as well as the records kept and, if applicable, incidents detected. d) Point out what action is taken in case a suspicious package is detected. e) Indicate how the inspection recording and, if applicable, the detected incidents are carried out.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, or renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The procedure for the selection of commercial partners must include indicators to detect clients or suppliers who may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, if applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new commercial partners and monitoring of partners already working with them (this includes any type of supplier that has a commercial relationship with your company; it is in the following sub-standard where it is requested to differentiate those at risk in your supply chain) and ensure it includes the following points: a) What information is required from your commercial partner. b) What aspects are reviewed and investigated. c) Indicators to identify clients or suppliers who may not be legitimate or with unlocated addresses. This point refers to pointing out all those alerts to determine that a commercial partner is not reliable and thus, conduct a deeper investigation and evaluate whether to work with them. d) Indicate if you maintain a file for each of your commercial partners, as well as the information it must contain. e) Point out how the services of your commercial partner are evaluated and what points you review.
The file must include at least the following: a) Company data (name, RFC, activity, etc.). b) Legal representative data. c) Proof of address. d) Commercial references (if applicable). e) Contracts, agreements, and/or confidentiality agreements. f) Security policies. g) If applicable, certificate or certification number in the security programs to which they belong.
4.2 Security requirements. The transport company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in its supply chain such as, subcontracted transporters, Customs Brokers, Private Security, warehouses, parking lots, companies providing Transport Media Repair services, Providers of Loading and Unloading services, cleaning service providers, private security, personnel hiring, high-security seal suppliers, collection and recycling, in addition to those resulting from the analysis performed. The requirements must be based on the Land Auto Transporter Profile established by AGACE, or if it exists, the specific Profile for each actor in the supply chain corresponding to them. The company must request from its commercial partners the documentation that certifies and proves that they comply with the minimum security standards established in this Land Auto Transporter Profile, either through a written declaration issued by the partner's legal representative, agreements, or contractual clauses backed by documentation supporting compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the transport company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of the company's commercial partners that provide their services within the facilities, they must be obligated to comply with these supply chain security requirements, for example, companies providing gardening, cleaning, cafeteria services, etc.
Response: Explanatory Notes: Describe the procedure indicating how you carry out the identification of commercial partners that require compliance with minimum security standards and how these comply with said requirements. Ensure you include the following points: a) A register of commercial partners that must comply with security requirements, and mention what type of providers these are (transporters, warehouses, custodian services, security company, transport media repair services, loading and unloading service, customs brokers, etc.). b) Indicate how you documentally ensure (agreements, accords, contractual clauses, and/or addenda) that your commercial partners comply with security requirements. c) Indicate if there are agreements, accords, contractual clauses, and/or addenda regarding the implementation of security measures with your service providers inside your company, such as: security guards, cleaning and maintenance services, etc.
d) Indicate whether you have business partners who are required to belong to a supply chain security program, whether certified by a foreign authority or the private sector (for example: CTPAT or any other World Customs Organization Authorized Economic Operator Program), as well as the information and documentation requested of them.
4.3 Business Partner Reviews. The company, through the Security Committee, must conduct periodic security assessments (as well as those derived from risk situations) of the processes and facilities of business associates based on a risk analysis, to ensure they meet the minimum security standards required by the company based on the Authorized Economic Operator Program. It must maintain records of these assessments, which allow verification that security processes and measures are being executed, as well as the corresponding follow-up.
When inconsistencies are found, the transport company must communicate this to its business partner and provide a justified period to address the observations or areas for improvement identified, or otherwise implement necessary measures to sanction them.
Conducting security assessments of business partners is important to ensure that there is a solid and functioning security program. Therefore, in addition to a documented procedure, there must be a program or schedule for the execution of these security reviews or assessments, prioritizing partners that are more critical according to their risk analysis. If a member is not assessed and the company is unaware of whether the processes and facilities of its business partners are functioning correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure for conducting security assessments to verify the security requirements of your business partners. Ensure you include the following points: a) The frequency with which visits to the business partner are made (these must be at least once a year and derived from risk situations). b) Record or report of the verification and, if applicable, the corresponding follow-up. c) Program or schedule for the execution of security reviews. d) The verification format(s) must be properly filled out, including the date, name, and position of those participating in the review, signatures, etc. e) Indicate what action measures are taken if business partners do not comply with the established security requirements.
If you have business partners with CTPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed, how you record it, and the actions you take if it is detected that it is suspended and/or cancelled, in accordance with what is established in your procedure.
The procedure must include: a) Frequency of visits. b) Security review points. c) Preparation of reports. d) Feedback and agreements with the business partner. e) Follow-up on agreements. f) Measures in case of detecting non-compliance with requirements. g) Record of assessments. h) Area or person responsible for carrying out this procedure.
Likewise, established procedures must exist to prevent, detect, or dissuade undeclared materials or unauthorized personnel from accessing means of transport and containers. These control measures and procedures must be documented with the intention and objective of maintaining the integrity of the means of transport and the import and export shipment at all times from the point of origin to its final destination.
5.1 Process Mapping. There must be a process map that describes step by step the operational flow for the transfer of foreign trade merchandise along the supply chain, including in an illustrative but not exhaustive manner, with respect to the service requested by the client, the following: assignment of the means of transport, container, trailer, inside and outside yards according to availability, entry into the facilities of the manufacturer, supplier, or seller, which describes the loading and unloading of merchandise, transfer with authorized routes and rest points. If any part of the transport is subcontracted within your supply chain, it is essential that it be considered within your risk analysis and process mapping, since the more direct and indirect suppliers there are, the greater the risk involved.
Likewise, the land transport company must have written procedures for the designation of operators/drivers, previously designed routes, collection of cargo, and delivery of foreign trade merchandise to the final destination; handling of documentation specific to the shipment during loading and/or unloading maneuvers or in advance; communication during the route of the shipment between intermediate or final points, its relationship with other actors in the supply chain such as logistics operators, Customs Brokers, among others, and contracting clients.
Response: Explanatory Notes: Attach the documented procedure where you describe in detail the process mapping or operational flow of your general transport service and the type of service you provide, which includes the designation of operators/drivers, vehicles/units, previously designed routes, cargo collection and delivery, handling of documentation, communication during the operation with other actors in the supply chain, handling and storage of foreign trade merchandise (if applicable), manufacturing companies, manufacturers or assemblers, parts and/or spare parts suppliers, mechanical suppliers, or any other service including your contracting clients. With the aim of having each of the steps involved in the transportation of the merchandise until delivery at the final destination well identified.
The process mapping must include the names (RFC and legal name) of the companies that provide services to you in your logistics process. This mapping must include, at least, the following aspects: a) Service request. b) Assignment of Unit and container or Trailer. c) Assignment of Operator. d) Service confirmation. e) Instructions to the Transporter. f) Cargo collection.
For the purposes of the administrative management and billing process, the transport company must have a documented procedure to receive and register the service request that the user will require, which must contain, at least, the service request, which includes in an illustrative but not exhaustive manner at least the following information: a) Origin (Collection). b) Destination. c) Cargo specifications (domestic, international, hazardous, high value, etc.). d) Time and date of delivery. e) Cost per freight. f) Insurance:
5.2 Delivery and Receipt of Cargo. The transport company must inform the operators/drivers of the transport that carry out the delivery or receipt of foreign trade cargo of the criteria and conditions that its clients (manufacturers, suppliers, etc.) require for the handling of their cargo, as well as comply with the security guidelines that the company has to enter their facilities at the time of collection and/or delivery of foreign trade cargo. The transport company must provide its clients, prior to their delivering the shipment and before loading and unloading maneuvers are carried out in the vehicles designated for such purposes, information regarding the operators/drivers so that they can be fully identified upon arrival at their facilities. The transport company must have an updated database with detailed information about its operators/drivers.
The operator/driver must know the documents that will be delivered to them, which cover the ownership of the cargo to be transported, such as the dispatch or transfer order, as well as the instruction sheet that will precisely establish the contact data of the person to whom they must direct themselves in case of any incident, inspection by another authority, or modification of the original conditions of the shipment, routes designated by the client, among others.
Likewise, with the documentation delivered to them, they must verify at the time of loading and unloading the merchandise the number of packages and the assigned locks described in them.
Furthermore, the transport company must issue a bill of lading duly documented for each shipment, which must contain, in addition to fiscal requirements, the applicable provisions contained in the Federal Self-Transport and Auxiliary Services Regulations.
Prior to loading the merchandise, the operator must inspect the vehicle to ensure that the means of transport is free from visible contamination by pests.
Additionally, training must be provided to transport operators to review import and/or export documentation in order to identify or recognize suspicious cargo shipments, such as: a) Originating from or destined to unusual places; b) Different routes; c) Cash payments; d) Unusual shipping and/or receiving practices; e) Lack of information.
Response: Explanatory Notes: Attach the documented procedure in which you indicate step by step how the delivery and receipt of the cargo is carried out, including: how you assign the operator and the means of transport, how the arrival time at the companies' facilities for cargo collection and delivery is established, and how you guarantee that the means of transport is free from visible contamination by pests. If any type of visible pest, contamination, trash, insects, grass, weeds, or brush is identified, how it is reported and what actions are taken regarding it.
5.3 Cargo Tracking Procedure. The transport company is responsible for monitoring the integrity of the means of transport, as well as the merchandise from the moment of loading until its delivery at the destination established, so it must have documented procedures that establish the use of technology for the tracking and supervision of activities of the movement of the means of transport that transfers foreign trade merchandise for land transfers.
There must be a device capable of tracking the position of the vehicles in which the merchandise is transported via GPS/Satellite Link during the time the transfer lasts, having continuous geographical coverage during the route. Said device must have the following characteristics: a) Ensure that the device cannot be removed from the unit to which it was fixed without this being detected and authorized. b) Recognize a Geofence (deviation limit). c) Know the position of the vehicle at all times. d) The device must have a Unique Identification Number (serial number). e) When an alert is detected, the device must be able to automatically change the transmission of the vehicle's position, so that it is reported every fifteen minutes, as long as the condition that triggered the alert remains. f) The device must be autonomous in its operation; that is, it does not require energy from the vehicle during its journey.
It is required that the device have an alert scheme, at least for the following cases: a) Device outside Geofence. b) Device exceeds immobility time. c) Vehicle exceeds time of stay in the country. d) Unauthorized removal of the device.
Likewise, the transport company should have a coupling device, sensor connector, or equivalent technology from the tractor to the trailer to ensure that the latter is also monitored and tracked, preventing said device from being removed and being able to have alerts that indicate the place, date, and time of hooking and unhooking.
Similarly, the company must establish documented procedures to ensure at all times the location of the transport vehicle in transit. These procedures must be carried out under a risk analysis that includes, in an illustrative but not exhaustive manner, the identification of predetermined routes, estimated delivery times, as well as between intermediate points, as well as overnight and/or rest (yards, pensions, exit customs, customs broker agency facilities, freight agents, authorized food stops, fuel loading, routine mechanical inspections, among others), which must be recorded and incorporated into the tracking process. Likewise, measures and actions to be taken in case of identifying any delay in the route due to weather conditions, traffic, mechanical incident, route changes, or inspection by an authority or any security incident must be included. There must be trained and authorized personnel for the permanent monitoring and/or traceability of shipments that transport foreign trade merchandise.
The monitoring, tracking, supervision, and registration data of all vehicles in transit that transport foreign trade merchandise (whether they cross into the United States of America and/or to any other country) must be preserved for one year in case the authority and/or the transport company must carry out an evaluation due to a security incident and/or for audit purposes. If you have contracted the services of a subcontracted provider for the merchandise transport service, the company must have access to the GPS monitoring system of its transporter, so that it can track the movement of its shipments.
If, as a result of monitoring and tracking, a real (or actualized) threat to the security of a shipment or means of transport is identified, the company must alert (as soon as possible) the business partners in the supply chain that may be affected and, if applicable, the authority as appropriate.
If the driver makes stops during their journey, they must register them and carry out inspections of the means of transport, containers, trailers, and semi-trailers used as Instruments of International Traffic, as well as of the closing devices, seals, and/or locks to verify their integrity and identify signs of manipulation before resuming the journey. Likewise, the driver must be able to recognize, act, and report when threats arise during the transfer of the units, such as: attempt at robbery, kidnapping, among others.
With the objective of guaranteeing that tracking and monitoring procedures are followed, in addition to supervising the correct filling of related records, management must involve itself in the surveillance and monitoring of cargo vehicles on the route, so it must participate in the periodic performance of documented random reviews of the tracking and control procedures. These random reviews must comprise the verification of the tracking records carried out by the responsible area against GPS records or route histories, to verify delivery time indicators, intermediate points, overnight and/or rest.
Response: Explanatory Notes: Describe how you carry out the review of predetermined routes based on your risk analysis individually or collectively with your clients and how it is documented.
Likewise, the monitoring of shipments must be documented, and this record must contain the following information: a) Name of the Operator. b) Origin and destination of the service. c) Client. d) Type of cargo. e) Records of the unit's location. f) Driver's hours of service logbook, which is a daily record containing the necessary data to know the effective driving time and determine rest in accordance with the Federal Highway Traffic Regulations.
Attach the documented procedure to perform the monitoring of vehicles or means of transport that transfer foreign trade merchandise. The procedure must include, in an illustrative but not exhaustive manner, the following: a) The area and person(s) responsible in the transport company for tracking and monitoring shipments. b) Indicate who are the people authorized to monitor and/or track foreign trade operations and how they have been instructed and trained to perform this work. c) Indicate by what form and/or systems they perform the monitoring of shipments. d) Have GPS whose external hardware is hidden and that can resist attempts to remove it, indicate the type of system implemented in the units you use and, if it is a third-party or subcontracted service, describe the consultation tools you have available to monitor the merchandise. e) In the case of geofences, within their parameters, minimum tolerances allowed for the predetermined transit route must exist or be established. f) Frequency to review the status of shipments and according to your risk analysis. g) Indicate the means of communication that exist with the unit operator (indicate if there is more than one way to communicate: Cell phone, tracking system, global positioning systems (GPS), fixed supervision points, etc.). h) Indicate the frequency with which clients are informed of the location of their shipments, or if they share any tracking system. i) Have systems or procedures with instructions to respond to significant route deviations and in case of any delay (stoppages, changes or diversions of route, mechanical failures, accidents, etc.) for arrival at the loading area, transfer points (exchange of boxes and semi-trailers) or final destination. Likewise, drivers must notify (to their supervisor and if applicable to the sender or consignee of the merchandise) any significant delay in the route due to weather, traffic, accidents, mechanical failures, route change, when the operator identifies that they are being observed or followed during the transfer of the merchandise, custody of units, etc. And on its part, the company must independently verify the cause of said delay.
j) The procedure must also include, in the event a real or concrete threat to the security of a shipment or means of transport is identified, how the company informs its commercial partners in the supply chain who may be affected, and, where applicable, the relevant authority, regarding these types of incidents or presumptions.
5.4 Processing of information and documentation of the cargo.
Carrier companies must have written procedures to ensure that both the electronic and/or documentary information sent by their clients starting from their service request, during the movement and transfer of the merchandise, as well as the information received by business associates, is legible, complete, accurate, reported in a timely manner, and protected against changes, loss, or the introduction of erroneous information.
Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use.
Response: Explanatory Notes: Attach the documented procedure for the processing of cargo documentation. Briefly explain what it consists of. a) Detail how you receive and transmit relevant information and documentation regarding the transfer of foreign trade merchandise with your commercial partners (Indicate if you use a specific computer control system and briefly explain its function). Furthermore, detail how you ensure that the provided information is legible, complete, accurate, reported in a timely manner, and protected against changes, loss, or the introduction of erroneous information. b) The electronic information of shipments and cargo in general must include the seal and/or lock number with which the cargo was secured.
The carrier company must have documented procedures, in which internal and operational policies are established, as well as the necessary controls for the due compliance of customs obligations.
6.1 Customs Obligations.
For the case of carrier companies that enter fiscal or supervised premises for the transfer of foreign trade merchandise, they must have a documented procedure for obtaining the CAAT registration, in accordance with what is established in articles 1 and 20 of the Law and rule 2.4.5.
Carrier companies that have registration in the register of carrier companies for merchandise in transit, in accordance with rule 4.6.11, must have a documented procedure with the objective of complying with what is established in rule 4.6.18.
Regarding internal transits of foreign trade merchandise referred to in articles 127 of the Law and rule 4.6.11, the carrier company must have a documented procedure that guarantees notice to customs authorities caused by late arrival, stating the causes that originated the delay, the location where the means of transport is, the transit entry number, and the status of the official locks, if any (article 188 of the Regulations).
For the purposes of what is stipulated in article 128 of the Law and rule 4.6.17, the carrier company, where applicable, must have a documented procedure that guarantees that the internal transit of the merchandise must be carried out within the maximum timeframes established in Annex 15.
For cases of destruction of merchandise provided for in article 94 of the Law and 141 of the Regulations, the carrier company must have a documented procedure by which it guarantees the delivery of notices in a clear, precise, and exact manner to the customs of destination.
Response: Explanatory Notes: Indicate if you have the CAAT and, if so, indicate your registration number. Attach the procedure that describes the steps to be followed for obtaining the CAAT (this procedure must include the steps to be followed to obtain the radiofrequency identification device number (transponder), in addition to including, who and how the information related to your vehicle fleet and transport operators is updated. Indicate if you have the Register to carry out the Transit of Merchandise, if affirmative, attach the following procedures: a) Documented procedure to comply with rule 4.6.18, which must include, in an enumerative but not exhaustive manner, the following:
Notices to the authority, regarding changes in the information provided for obtaining the registration.
Integrate and maintain updated a daily automated register of service users.
Integration of a file for each service user. b) Attach the documented procedure by which it guarantees notice to customs authorities caused by late arrival in accordance with article 188 of the Regulations. c) Attach the documented procedure referred to in article 128 of the Law in relation to rule 4.6.17, and if applicable, describe how you guarantee compliance with the timeframes established for transfers referred to in Annex 15.
Security of cargo vehicles, containers, trailers, and/or semi-trailers.
The security of means of transport, tractors, containers, trailers, and semi-trailers (including cargo vehicles, pickup truck type, van, or van, among others) must be maintained to protect them from the introduction of unauthorized persons and/or materials. For this reason, it is necessary to have documented procedures to review, seal, and maintain their integrity. Likewise, the process of inspecting said means of transport, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic, must include a procedure for agricultural inspections to look for visible pests and serious structural deficiencies. Pest contamination is defined as visible forms of animals, insects, or other invertebrates (living or dead, at any stage of the life cycle, including eggs, etc.), or any organic material of animal origin (including blood, bones, hair, meat, secretions, excretions, etc.); plants or vegetable products (including fruits, seeds, leaves, twigs, roots, bark, etc.); or other organic material, including fungi, dirt, or water; when said products are not the declared cargo within the Instruments of International Traffic.
In the event that high-security seals are used, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the loading point. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must meet or exceed the ISO 17712 Standard for high-security seals.
With the objective of maintaining supply chain security, the carrier company must inspect all cargo vehicles systematically upon entry and exit from its facilities (domestic and international traffic), in addition to keeping a record.
7.1 Use of seals and/or locks in containers and trailers.
The use and placement of seals or locks on means of transport (containers, trailers, and semi-trailers) is considered a critical and necessary process to maintain the integrity of shipments that transport foreign trade merchandise. Therefore, the carrier company must document procedures that include the control, safeguarding, assignment, handling of discrepancies, replacement, and destruction of locks and seals that meet or exceed the ISO 17712 Standard.
The carrier company must have a documented procedure where the means of transport are identified, and, if applicable, the containers, train cars, and/or semi-trailers used in its international logistics chain, and indicate how their integrity is maintained.
For this reason, as one of the security mechanisms, the carrier company must use High Security locks or seals that meet or exceed the ISO 17712 Standard in all loaded containers and trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. For this, the carrier company must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when they are opened by any authority.
In the event of such an inspection, drivers must notify and record any anomaly or unusual structural modification found in the means of transport derived from said review. The procedures must include the steps to be followed if it is discovered that a seal is altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to the commercial partners involved in the supply chain, and the investigation of the security incident; these must be notified to security personnel, commercial partners who may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program.
The carrier company must verify and evidence that during loading points, as well as in reviews by any authority or due to changes in the original conditions of the shipment, high-security seals or locks that meet or exceed the ISO 17712 Standard are correctly applied and placed; for the case of consolidated cargo collection and delivery operations that do not use consolidation centers to sort or consolidate the cargo before arriving at the destination, the carrier company must, at each stop and before arriving at the destination, place high-security seals on the trailer, semi-trailer, or container. The company's management or a security supervisor must perform periodic and documented audits of the high-security seals and/or locks; these reviews must include the verification of the inventory of stored seals and/or locks and the cross-check with inventory records and shipping documents.
Likewise, the company must have documented procedures that clearly describe how high-security seals will be controlled by the transporter during route transit, and that, in an enumerative but not exhaustive manner, contain the following: a) Verify the correct placement of seals or locks in accordance with the VVTT inspection method to evidence and discard improper manipulations:
Response: Explanatory Notes: Describe the documented procedure for the review of seals and/or locks in vehicles, means of transport, containers, trailers, and/or semi-trailers. This must include, among other aspects according to your operation: a) Verify that the seal or lock is intact and determine if there is evidence of improper manipulation. b) Use the VVTT inspection method. c) Review and cross-reference the documentation containing the number of the original seal or lock and, if applicable, the additional ones carried during the transfer of the merchandise. In the event of using a replacement seal and/or lock, said number must be registered within the carrier company's control. If altered seals and/or locks are identified, they must be kept to help carry out the investigation of said incident or discrepancy and, as appropriate, report the compromised seals and/or locks to the foreign authority. d) Review that the closing devices, hinges, and pins are attached to the trailer or container, and welded or riveted. Also, protective plates can be placed on the door hinges and/or a seal/adhesive tape placed on at least each side. Also, the correct functioning of handles, latches, and all other locking or closing mechanisms of the cargo vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device. e) Indicate how you assign and replace high-security locks, in the event that, during the route, it is inspected by another authority. If a seal and/or lock breaks in transit, the cargo must be examined, the number of the replacement seal and/or lock must be registered, and the driver (as well as the transport company) must immediately notify business associates when this happens, indicate who broke it, and provide the new seal number. Attach the documented procedure for the control and handling of seals and/or locks. This must include, among other aspects according to your operation: a) What type of seals and/or locks you use in your operations (foreign trade, transit, storage, etc.). b) Who has access and how locks and/or seals are safeguarded. The management of seals and/or locks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (register of seals that are used, as well as the receipt of new seals and/or locks. c) Describe how the company's management or the security supervisor participates in the audits of high-security seals and/or locks, the reviews they perform, the records they generate, and the actions they take in the event of identifying discrepancies. Also, how the supervisors of the shipping area and/or warehouse managers verify the seal numbers used in means of transport and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). d) How discrepancies in seal and/or lock numbers are addressed. e) Indicate who the supplier(s) is/are and how it is proven that the specifications of the seals and/or locks comply with the ISO 17712 Standard (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO). All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of means of transport, containers, trailers, and semi-trailers.
The carrier company must have procedures to permanently carry out a review of means of transport (tractors), containers, trailers, and semi-trailers used as Instruments of International Traffic, even the reliability of the door lock mechanisms, with the purpose of identifying natural or hidden compartments, using a checklist or format that includes the main points to review. Such review must be carried out by operators/drivers or personnel designated by the company for such effect. Likewise, the physical-mechanical conditions of the means of transport must be reviewed periodically to prove their good functioning.
The inspections of means of transport or cargo vehicles, containers, and trailers must be systematic, and carried out upon entry and exit from yards or storage sites and, if applicable, at the loading point of the merchandise (contracting company); and if the infrastructure allows, before arriving at the dispatch customs using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by alarm systems and closed-circuit television and video surveillance systems; said system must cover the inspection system in its entirety.
The documented procedure for its inspection must include, in an enumerative but not exhaustive manner, the following review points: Means of Transport | Containers, Trailers, and Semi-trailers
Likewise, before loading means of transport, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide smuggling or that they have been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of merchandise subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination. The driver must ensure before crossing that the cabin is clean and free of trash.
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of means of transport, containers, trailers, and semi-trailers. This must include, among other aspects according to your operation: a) Those responsible for carrying out the inspection. b) Definition of the place(s) where the inspection is carried out and indicate how it is monitored by alarm systems and closed-circuit television and video surveillance. c) The review points for means of transport, trailers, semi-trailers, and containers, both for security and those for quality and agricultural inspections with the purpose of looking for visible pests. d) Instructions for the driver to ensure before crossing that the cabin is clean and free of trash.
Attach the format you use to carry out the inspection that meets the minimum requirements indicated in this sub-standard. If you use other types of cargo vehicles for the transport of merchandise (vans, pickups, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points. Likewise, the security and agricultural inspection format must include the following information: a) Date of inspection; b) Time of inspection; c) Vehicle license plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected; and f) Name of the employee who performs the inspection and the supervisor. The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation: a) Regarding carrier companies of hazardous materials and waste, each vehicle must have a daily visual review log of the auto-transport unit. The documentation must be kept for one year for an investigation in the event of any security incident, as well as to demonstrate continuous compliance with these inspection requirements. Additionally, and based on risk analysis, the carrier company should carry out periodic random reviews of cargo vehicles to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the means of transport may be susceptible to contamination (maneuvering yard, loading and unloading areas, after loading the unit, and on the route to the United States of America border). Description of the place(s) where the inspection is carried out and indicate if it is monitored by alarm systems and closed-circuit television and video surveillance.
Likewise, describe the procedure performed on the means of transport, cargo vehicles, trailers, semi-trailers, and/or containers used as Instruments of International Traffic, to validate that they meet the physical-mechanical conditions for daily operation on federal jurisdiction roads and bridges, in addition to validating that they have records of this type of maintenance for at least one year.
This procedure must additionally include the following: a) Responsible personnel. b) Locations where inspections are carried out. c) In the event that any physical-mechanical condition and/or anomaly is detected that affects the proper functioning of the units, how they are reported, and what measures must be taken. d) Specify what type of record is kept.
In cases where, due to major structural modifications in the means of transport such as axles, springs, chassis modifications, and even adaptations in the cabins, among others, the owner and responsible party of the vehicle fleet must contemplate, in accordance with their risk analysis, a more exhaustive review of the vehicle in question to ensure its integrity. In this regard: a) Indicate whether the repair or maintenance of the transport units (tractors), containers, or trailers is carried out on-site or by an external provider. b) Briefly describe how the handover-receipt of vehicles that underwent modifications such as those mentioned in the previous paragraph is carried out.
7.3 Storage of vehicles, means of transport, containers, trailers, and semi-trailers. The transport company must maintain the integrity at all times of the means of transport (tractors, containers, trailers, and/or semi-trailers, among others) by establishing controls within its facilities. If these are empty and must be stored in parking areas, they must be secured with a lock and/or indicative seal, or, if applicable, in a secure area that is sheltered and/or monitored.
When it is necessary to store or overnight any container, trailer, and/or semi-trailer with foreign trade merchandise, it must be located in a secure area that has perimeter barriers and is monitored by alarm systems, closed-circuit television, and video surveillance, to prevent unauthorized access and manipulation of the unit and merchandise. Therefore, it must be closed with a high-security lock in accordance with ISO 17712 Standard.
If during the journey on the authorized route to the final destination, it is considered necessary to move to a facility authorized as a storage yard for vehicles, means of transport, containers, trailers, and semi-trailers, whether owned by the company or through a third party, the transport company must guarantee that these facilities meet the minimum criteria in terms of security based on this Ground Transporter Self-Assessment Profile established by AGACE, or, if applicable, another Authorized Economic Operator Program.
Answer: Explanatory Notes: Describe how the integrity of the means of transport carrying foreign trade merchandise (boxes, containers, trailers, and/or semi-trailers) is secured. Indicate the types of seals and/or locks used for boxes, containers, trailers, and/or semi-trailers. Indicate how many facilities the company contemplates for the storage of vehicles, means of transport, containers, trailers, and semi-trailers, and add the following data for each of these: a) Name or denomination of the facility. b) Full address of the facility. c) Surface area of the facility marked in m2. d) Indicate how many foreign trade shipments enter the facility (import/export). e) Number of people working in this facility. f) In case any facility has been visited by CTPAT, indicate the date the visit took place. g) Indicate in each of the facilities which one belongs to the company or is a service contracted through a third party. h) Describe how you ensure that your commercial partner providing the storage service meets the minimum requirements in terms of security.
8.1 Verification of work history. The transport company must have documented procedures to investigate and verify the information stated in the curriculum, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either independently or through an external company. Similarly, for positions that, due to their sensitivity, require it and affect the security of shipments subject to foreign trade, in accordance with the risk analysis previously conducted, stricter requirements for hiring must be considered, which must be carried out periodically.
Regarding personnel already working in the company, periodic investigations must be conducted based on the activities and/or sensitivity of the employee's position. This procedure must contemplate the creation and updating of personnel files, which must have restricted access and contain the following information, enumeratively but not limitatively: a) Employment application. b) Updated photograph (in electronic or printed format). c) Copy of official identification. d) Copy of the current federal driver's license issued by SICT according to the type of service to be provided. e) Copy of updated proof of address. f) Copy of birth certificate. g) Registration with Social Security Institutions. h) Recommendation letters. i) Evaluations (Mandatory Toxicological Exam for operators/drivers) at least every six months. j) Hiring terms. k) Minimum mechanical knowledge exam. Similarly, for sensitive positions identified in the previously conducted risk analysis and directly affecting the security of means of transport, stricter requirements for hiring must be considered, which must be carried out periodically (e.g., Operators/drivers).
Answer: Explanatory Notes: Describe the documented procedure for hiring personnel and ensure you include the following: a) Requirements and documentation demanded. b) Tests and exams requested. Indicate the areas and/or critical positions identified as risky, according to your analysis, and indicate the following: a) Indicate what the additional requirements are for specific areas and/or work positions such as criminal records (if legislation and company policies allow), certificate of no criminal record, socioeconomic studies, clinical studies, toxicological (drug use), etc. If applicable, indicate the positions or work areas where they are required and with what frequency they are carried out. b) Indicate whether, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. The procedures for hiring personnel and contractors may include: a) Thorough investigations of the work and personal backgrounds of new employees. b) Confidentiality and liability clauses in employee contracts. c) Specific requirements for critical positions. d) If applicable, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. f) Indicate the medical and toxicological exams performed on operators/drivers. g) In case of hiring a service agency for personnel hiring, indicate if it has documented procedures for hiring personnel and how you ensure they comply with the same. Briefly explain what they consist of. h) The company may consider the results of background verifications of candidates, as allowed by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel termination procedure. Documented procedures must exist for personnel termination, which must include the handover of identification, and any other items provided to them to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include termination in those systems, both computer and access, among others that may exist.
Answer: Explanatory Notes: Describe the procedure for personnel termination, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the handover and confirmation of identification, uniforms, keys, and other equipment is carried out. c) Indicate the control, record, and/or format, in which the handover of material is identified and secured, and termination in computer systems (if applicable, attach). d) Specify the type of records of personnel who ended their employment relationship with the transport company, so that in case it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The transport company must maintain an updated system, control, or database of active employees. Likewise, the registration of affiliation with Social Security Institutions and other legal labor records must be carried out and kept updated. In the case where the company has personnel hired by its commercial partners and working within the facilities, it must ensure that they meet the requirements established for the rest of its employees.
Answer: Explanatory Notes: Indicate whether the company has an updated system, control, or database, both for personnel hired directly, and that hired through a service provider company, and ensure it includes enumeratively but not limitatively the following points: a) Full name. b) Updated photograph at least every five years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). d) Affiliation. e) Work history. f) Diseases. g) Medical exams. h) Training. i) Type of license and status thereof (they must have a record of transporter licenses with the corresponding validity, in order to prevent their drivers from traveling with expired licenses). j) Results of periodic evaluations. k) Observations. l) This personnel must be hired in accordance with current labor laws and regulations.
9.1 Classification and handling of documents. Procedures must exist to classify documents according to their sensitivity and/or importance, with special emphasis on that received from their contractors where information related to routes, materials, merchandise, and/or goods being transported, instruction letters, schedules, customer and/or contact names, among others, is described. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. Reviews must be conducted regularly to ensure that documents are not used improperly. The useful life of documentation and/or files must be identified, and procedures for their destruction must be established. a) The company must have updated and safeguarded files of means of transport, containers, trailers, and semi-trailers, with the following:
Answer: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: a) Control register for delivery, loan, among others of documentation. b) Restricted access to the archive area. c) Storage and classification policies. d) An updated security plan describing the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. e) In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards, which must be communicated through a training program for all employees handling computer equipment and systems, including topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must employ secure technologies, such as Virtual Private Networks (VPN), to allow employees to access the company intranet securely when outside the office, as well as procedures designed to prevent unauthorized remote user access. Therefore, written procedures and infrastructure must exist to protect the company against loss, theft, leakage, hacking, and/or ransomware of information. This includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as an established system to identify the abuse of Information Technology systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, including phrases or other forms of authentication. Users of such Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
Answer: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how you back up and ensure the security of your information, in addition to protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which backups are carried out. b) Who has access to them, and who authorizes the recovery of information. c) Indicate what type of tests you perform and how often, to verify the security of the network, systems, and infrastructure. d) Mention if, to carry out this type of tests or vulnerability scans, you do so through software, a third party, or provider, and if so, indicate the name or corporate name. e) In case vulnerabilities are found, describe the corrective actions that must be implemented. f) Indicate if you share information about cybersecurity threats with your commercial partners participating in your supply chain (for example: communications, bulletins, emails, etc.). g) Systems must be protected by passwords and changed frequently; therefore, indicate the procedure for changing them. h) Indicate if there are information security policies for their protection. i) Have a system or software to detect and identify abuse, intrusion, or access by unauthorized persons to your Information Technology systems and/or data, as well as the abuse of policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology systems and security policies. Information Technology and cybersecurity policies and procedures must be reviewed annually and updated due to an attack or according to situations that may put the company's systems at risk. Describe the security measures you use to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when outside the office. In case of allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the transport company's information must also include: a) How and for how long data is stored. b) Business continuity plan in case of incident and how to recover information. c) Frequency and location of backups and archived information. d) If backups are stored in sites alternative to the facilities where the data processing center is located. e) Tests of the validity of data recovery from backups.
The procedures regarding the protection of the company's information must also include:
a) An updated and documented policy for the protection of the company's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format.
b) Detail whether the company operates with multiple systems (headquarters/sites) and how these systems are controlled.
c) Who is responsible for the protection of the company's computer system (responsibility should not be limited to one person but to several so that each can monitor the actions of the others).
d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and levels of access to computer systems are granted (access to sensitive information must be limited to authorized personnel to modify and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements.
e) Indicate the elements or format that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or which area provides these passwords.
f) Indicate the name of the "firewall" and anti-virus used (include licensing information), providing evidence that this security software is active and receives periodic updates.
Therefore, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses (software and hardware).
All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence.
When these technological equipment must be disposed of, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed properly to avoid information leakage.
g) In the event of employee termination, access to computer equipment, telecommunications, and the network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc.
h) Elimination, maintenance, or updating of user details.
i) Measures planned to handle incidents in case the system is compromised.
10.1 Training and awareness on threats. The transport company must have a training and awareness program on security policies in the supply chain directed to all its employees (operational and administrative) and, additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. The company must have an additional program for its operators/drivers used for the transport of goods destined for foreign trade, which includes specific topics according to their functions that allow them to maintain the integrity of the means of transport and their cargo, handling of incidents, changing locks in case of inspection by other authorities, when the operator identifies that they are being watched or followed during the transport of goods, among others, that are implemented. Likewise, specific training must be offered according to their functions to help employees maintain the integrity of trailers and tractors for agricultural and security purposes, reception and review of mail and packages, prevention of operations with proceeds of illicit origin (money laundering, terrorist financing, etc.), how to recognize and report internal conspiracies and protect access controls, as well as training regarding smuggling, merchandise theft, placement of seals and high-security locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee induction and periodically maintain update programs. Update training must be carried out periodically, after a security incident and when there are changes in the transport company's procedures. In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or ransomware of information), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee induction and periodically maintain update programs. Update training must be carried out periodically, after a security incident and when there are changes in the company's procedures. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company, and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. The foregoing, in accordance with the regulation established by SICT, which establishes that permit holders have the obligation to provide their drivers with training and coaching to ensure that the provision of services is efficient, safe, and effective.
Response: Explanatory Notes: The company must have a training program on security and prevention in the supply chain for all employees (administrative and operational). Briefly explain what it consists of and ensure you include the following: a) Brief description of the topics taught in the program. b) When they are taught (induction, specific periods, etc.). c) Frequency of training and, if applicable, updates. d) Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all the objectives of the same. e) Explain how employee participation in security matters is encouraged. The topics that must be included, by way of example and not limitation: a) Access and security policies at the facilities. b) Delivery-receipt of merchandise. c) Confidentiality of cargo information. d) Transport instructions. e) Accident and emergency reports. f) Instructions for placing locks and/or seals in case of inspection by other authorities. g) Installation and testing of security alarms and unit tracking, when applicable. h) Identification of authorized formats and documents to be used.
Training to perform the review of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments; b) Smuggling hidden in natural compartments; c) Signs of pest contamination; d) Procedures to follow if something is found during an inspection of the means of transport or if a security incident occurs during transit; e) Agricultural review training must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials, and the identification of infested wood. Operators and personnel who perform agricultural and security inspections of means of transport must be trained to inspect cargo vehicles for such purposes; therefore, describe how you comply with the provisions established by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144 SEMARNAT-2017, in accordance with International Standards for Phytosanitary Measures No. 15, entitled: Regulation of wooden packaging used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations, and the identification of infested wood.
11.1 Reporting of anomalies and/or suspicious activities. In the event of detection of anomalies and/or suspicious activities related to the security of the supply chain and in accordance with your logistical processes (related to access control, delivery, receipt, and storage of merchandise, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and/or other competent authorities, keeping a record of such anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as those containing mechanisms to anonymously report problems related to security; ensure you include the following: a) Who is responsible for reporting incidents. b) Detail how you determine and identify with which authority to communicate in different scenarios or presumption of suspicious activities. c) Mention if you keep a record of the reporting of these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that so require. This information and documentation generated to carry out foreign trade operations must be included in a file for the purpose of allowing the identification of each of the processes the means of transport went through, up to the point where the incidence was detected, and allowing the recognition of the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation, in the event of any security incident, and ensure you include the following: a) Responsible for carrying out the investigation. b) Documentation that integrates the investigation file. c) Information related to the operator(s)/driver(s), vehicles (tractors), containers, trailers, and/or semi-trailers, merchandise, and routes. The documents to be included in the file derived from the investigation, by way of example and not limitation, may be: a) General information of the shipment, Purchase Order. b) Transport request; Confirmation of means of transport; Identification of transport operator (Access records, etc.). c) Container Inspection Formats; Exit order; delivery records. d) Videos from alarm systems, closed-circuit television, and video surveillance. e) Documentation generated for the carrier (Packing list, Bill of Lading, instruction sheet). f) Documentation generated for business partners (Description of merchandise, Proformas, invoices, etc.). g) Documentation generated by the business partner (Customs declarations, Manifests, Tracking and inspection reports, videos if applicable, etc.). h) Tracking and monitoring report of the unit (GPS Tracking).
E6. Courier and Package Profile. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization. General Information The objective of this Profile is to ensure that courier and package companies have security practices and processes implemented in their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products. Courier and package companies interested in obtaining the authorization referred to in Rule 7.1.5. must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards, the application of a risk analysis culture supported by decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the company itself. In the event that the courier and package company has authorization for a Fiscalized Facility or Strategic Fiscalized Facility; in addition to complying with what is provided in this document, it must accredit the requirements and guidelines established for the control, surveillance, access routes, infrastructure, equipment, and security of foreign trade merchandise established by ANAM and may prove compliance with that which coincides with what is established in this Profile. Filling Instructions:
You must fill out a Courier and Package Profile for each of the main facilities where you consolidate foreign trade merchandise and, if applicable, for those related facilities such as: warehouses, distribution centers, among others. The number of Profiles submitted must coincide with the facilities manifested in your application for inscription as a Certified Business Partner under the category of courier and package and with the domiciles registered with the RFC.
In each sub-standard, the courier and package company must detail how it complies with or exceeds what is established in each of the numerals as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Description of the standard 1.1 Sub-standard. Description of the sub-standard Response: Explanatory Notes: Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards; therefore, you must attach the procedures in Spanish that, if applicable, are required, or provide a detailed explanation of what is requested in the Response field. The section regarding Explanatory Notes is intended to be used as a guide regarding the points that must be included in the Response or in the attached procedures, as appropriate, for each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once this Courier and Package Profile is answered, you must attach it to the Registration Application in the Business Certification Scheme, Certified Business Partner modality referred to in the first paragraph of Rule 7.1.5., first paragraph, fraction VI, subsection e). For the purpose of verifying what is manifested in the previous paragraph, SAT through AGACE may conduct an inspection of the facility, exclusively for the purpose of verifying what is manifested in this document.
Any incomplete Courier and Package Profile will not be processed.
Any question relative to the Inscription Application and the Courier and Package Profile, direct it to the contacts that appear on the SAT Portal.
In the event of being authorized as a Certified Business Partner, this format must be kept updated, and notify when the circumstances under which the registration was granted have varied and as a result changes or modifications are required in the information stated and provided in this Courier and Package Profile to the authority in accordance with what is established in Rule 7.2.1., fourth paragraph, fractions I, II, and VII.
When, as a result of the inspection visit, non-compliances related to minimum security standards result, the applicant may remedy them before the issuance of the resolution established in Rule 7.1.6., for which it will have a maximum period of three months counted from the notification of the stated non-compliances. Installation Data A Courier and Package Profile must be filled out for each of the cargo consolidation facilities that handle merchandise subject to foreign trade, if applicable, for those related facilities such as: warehouses, distribution centers, consolidation, etc. Installation Information Courier and Package Profile Number: from RFC Name and/or Business Name Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federative Entity Age of the installation (years of operation): Activity performed in the installation: Preponderant products handled in the installation of the courier and package company: (As applicable) Average number of monthly shipments (EXP): (By maritime, air, land, rail, etc. transport) Average number of monthly shipments (IMP): (By maritime, air, land, rail, etc. transport) Total number of employees at this installation: Surface area of the installation (m2):
Certifications in security programs: (Indicate if this facility holds a certification from any of the following programs) CTPAT Yes No Level: Pre-Applicant: Applicant: Certified: Certified/Validated: CTPAT Account number (8 digits): Date of last visit to this facility: Authorized Economic Operator from other countries (AEO) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration: Certifications: (Indicate if you hold certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The courier and package company must establish measures to identify, analyze, and mitigate security risks that could result in alterations to foreign trade merchandise during its handling, guarding, custody, and transport in its supply chain and facilities, under the guideline of a documented procedure. This analysis must be based on the organization's model (e.g., facility locations, type of merchandise, volume and country of origin, clients, suppliers, routes, information leakage, personnel hiring, classification and handling of documents, Information Technologies, potential threats, etc.), so that it allows implementing and maintaining appropriate security measures. Based on the above, the company must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be updated at least once a year, so that it allows permanently identifying new threats or risks considered in the operation, as a result of some security incident or that originate from changes in initial conditions, as well as to identify that the policies, procedures, control mechanisms, and security are being complied with. It is important to note that the company's Security Committee must participate in the drafting and updating of the risk analysis, as well as in the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate which are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the facilities of your company, make sure to include the following points: a) Indicate the periodicity with which you review and/or update the risk analysis. b) Indicate which aspects and/or areas of the company are incorporated into the risk analysis. c) Describe the methodology or techniques used to perform the risk analysis. d) Mention who are the responsible for reviewing updating the risk analysis. Likewise, the documented procedure to identify risks in the supply chain and its facilities, must contemplate the process of risk appreciation and management, and include the following aspects: a) The context (cultural, political, legal, economic, geographic, social, etc.) of the installation. b) Identify risks in your supply chain and your facilities. c) Risk analysis (causes, consequences, probabilities and existing controls to determine the level of risk as high, medium and low). d) Risk evaluation (decision making to determine the risks to treat and priority for implement the treatment). e) Risk treatment (application of alternatives to change the probability that risks occur). f) Risk monitoring and review (monitoring of the results of the risk analysis and verification of the efficacy of its treatment). It is suggested to use the techniques of Administration, management and evaluation of risks according to international standards ISO 31000, ISO 31010 and ISO 28000 that according to your business model, should implement.
1.2 Security Policies. The courier and package company must have a policy oriented towards preventing, securing, and recognizing threats to the security of the supply chain and company facilities, such as drug trafficking, money laundering, arms trafficking, human trafficking, prohibited goods, acts of terrorism. To promote a culture of security, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The senior officials or executives of the company who must endorse and sign the security policy can be the company president, the chief executive officer, the general manager, the security director, or personnel with a comparable position with decision-making authority.
Response: Explanatory Notes: Enunciate the security policy oriented towards preventing, securing and recognizing threats in the supply chain and facilities, of the company, indicate who is the responsible for its review, signature and dissemination to employees, as well as the periodicity with which its update is carried out. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the initial training and of reinforcement of the company.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year, under the guidelines of a documented procedure that allows evaluating all processes regarding security in the supply chain and its facilities in a more critical and deep manner, as well as guaranteeing that its employees follow the company's security procedures. The audits must be carried out by the company's Security Committee, establish a documented procedure, as well as a program or calendar for their realization. Although it is necessary that the audits are focused on supply chain security and based on the evaluation, review, and execution of minimum standards in terms of security, their focus must be adjusted to the size of the organization, level of risks, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. Senior management must review the audit results, analyze causes, and undertake corrective or preventive actions required. The review process must guarantee that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to the fact that the points of contact of the courier and package company must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain, make sure to include the following points: a) Indicate how the courier and package company carries out the scheduling or calendarization to perform an internal audit, in terms of security in the supply chain. b) Indicate who participates in them, and the records that are generated, as well as the periodicity with which they are carried out. c) Indicate how the company's management verifies the result of the audits in terms of security of the supply chain and how it carries out and/or implements preventive, corrective, and improvement actions in addition to the follow-up and closure of the same. d) The formats used during internal audits must be properly filled out, and through them, evidence that the procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans related to Supply Chain Security. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and business resumption to ensure business continuity in case of affectation to the normal development of the activities and foreign trade operations of the company in its supply chain (during the transport, handling, storage, and custody of foreign trade merchandise according to its logistics process. A crisis or contingency can include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, customs closure, a bomb threat, the detection of suspicious packages, power outage, theft and/or damage to merchandise, threats or extortion, blockages or road closures, among others). The courier and package company must communicate these plans to personnel through periodic training, as well as carry out tests, practical exercises, and annual simulations of the contingency and emergency plans to verify their effectiveness, from which a properly filled-out and signed record must be maintained (for example: result reports, minutes or reports, which must be backed up by video recordings, photographs, etc., that demonstrate their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in case of an emergency or security situation, that affects the normal development of the foreign trade activities of the courier and package company. This procedure must include, by way of example and not limitation, the following: a) What situations it contemplates, describing the plan of action and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. b) What mechanisms it uses to guarantee that the plan of business continuity is effective. c) Contemplate the scheduling and carrying out of annual simulations and how they are documented (for example: result reports, minutes or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures and in case an irregularity has been detected, carry out the corresponding repair as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal routes, and the location of buildings must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others), and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damages to the facilities. Attach a distribution or architectural plan of the whole, where the limits of the facilities can be identified, access routes, emergency exits, location of the buildings, critical areas, parking lots, and boundaries.
2.2 Access at Doors and Booths. Entry or exit doors for personnel and/or vehicles must be attended, controlled, watched, and/or supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each one, and indicate how they are monitored (in case of having assigned security personnel, indicate the quantity). Detail if there are doors and/or accesses blocked, or permanently closed and their location. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the perimeters of the courier and package company's facilities, based on a risk analysis. Fences, interior barriers, or a mechanism to identify and segregate international cargo, as well as high-value and dangerous cargo, must be used. These must be inspected regularly and carry a record of the review with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks. Storage areas, high-value, dangerous, and/or restricted-access areas must be clearly identified and monitored to prevent unauthorized entry.
Response: Explanatory Notes: Describe the type of peripheral barrier and/or fences with which the installation is equipped, make sure to include the following points: a) Describe which areas are segregated. b) Indicate their characteristics (material, dimensions, etc.). c) In case of not having fences, justify detailedly the reason. d) Periodicity with which the integrity of the perimeter fences is verified, and the records that are carried out with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible. Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages. Describe how the cargo destined for foreign countries, dangerous material, and high-value cargo is segregated; make sure to include the following points: a) Indicate how you separate national merchandise and foreign trade merchandise, and if it is additionally identified (for example: different packaging; labels; packaging, among others). b) Identify and indicate restricted access areas (dangerous goods, high value, confidential, etc.). The procedure for the inspection of perimeter fences could include: a) Personnel responsible for carrying out the review. b) How and how often the inspections of fences, perimeter fences and/or peripheral barriers and buildings are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that the repairs and/or modifications meet the technical specifications and necessary security requirements.
2.4 Parking Lots. Access to the facilities' parking lots must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas.
Response: Explanatory Notes: Describe the procedure for the control and monitoring of the parking lots, make sure to include the following points: a) Responsible for controlling and monitoring access to the parking lots. b) Identification of the parking lots (specify if the visitor parking is separated from the storage and merchandise handling areas). c) How entry and exit control of vehicles to the facilities is carried out, indicate the records that are made for parking control, the existing control mechanisms (for example: badges, card readers, lanyards, etc.), how they are assigned and the area responsible for doing so. d) Policies or mechanisms to not allow the entry of private vehicles to the storage and handling merchandise areas.
2.5 Key and Lock Device Control. Windows, doors, and interior and exterior fences, according to their risk analysis, must be secured with locking devices. The company must have a documented procedure for the handling and control of keys and/or locking devices for interior areas that have been considered critical. Likewise, they must keep a record and establish control through signed responsibility letters by persons who have keys or authorized access according to their level of responsibility and tasks within their work area.
Response: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have closing or security mechanisms. Attach the documented procedures for the handling, and control of keys and/or locking devices, make sure that it includes the following points: a) Responsible for administering and controlling the security of the keys. b) Format and/or control record for the loan of keys. c) Treatment of loss or non-return of keys. d) Indicate if there are areas in which access is with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of people, material, and/or equipment located there, including the following areas: entrances and exits, handling, loading, unloading, and storage areas of merchandise, perimeter and/or peripheral fences, interior fences, and parking areas, and must have an emergency and/or backup system in sensitive areas.
Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system, make sure to include the following points: a) Indicate which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant or any other mechanism to supply electricity in case of any contingency). b) How you ensure that the lighting system is appropriate in each of the areas of the company in such a way that it allows clear identification of the personnel, material, and/or equipment located there. The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting.
2.7 Communication Devices. The courier and package company must have communication devices and/or systems with the purpose of contacting security personnel and/or emergency and security authorities as required. Additionally, it must have a backup system and verify its proper functioning periodically.
Response: Explanatory Notes: Describe the procedure that personnel must perform to contact the company's security personnel or, if applicable, the corresponding authority in case of any security incident. Indicate if operational and administrative personnel have or dispose of devices (landline phones, mobile phones, alert buttons and/or emergency, etc.) to communicate with security personnel and/or whoever corresponds (these must be accessible to users, to be able to have a prompt reaction). Indicate what type of communication devices the security personnel in the company uses (landline phones, cell phones, radios, alarm system, etc.).
Describe the procedure for the control and maintenance of communication devices, ensuring you include the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate whether you have backup communication devices in case the permanent system fails, and if so, briefly detail them. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Verification and maintenance records of the devices. c) Method of assignment of communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance. Alarm systems, closed-circuit television, video surveillance, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in facilities and other considered sensitive areas, notify the corresponding area, and also be used as evidence in investigations derived from any security incident. These security systems and technologies must be installed according to a prior risk analysis so that areas involving the handling, loading, unloading, and storage of goods, security inspections of cargo vehicles, as well as the access of personnel, visitors, suppliers, passenger and cargo vehicles, and other considered sensitive areas are permanently and uninterruptedly monitored, supervised, and overseen, in accordance with what is established for this effect by ANAM and simultaneous operation with the customs office or area in question. This applies in cases where courier and package companies are located within a supervised facility and/or outside of it. These systems must allow clear identification of the area or environment being monitored and maintain a backup of recordings for at least one month, considering that if your logistical processes exceed this period, the backup retention period must be increased, in order to have the necessary elements to assign corresponding responsibilities in case of a security incident. The courier and package company must have a documented operational procedure. For alarm systems, closed-circuit television, video surveillance, and security technologies, this must include supervision of the equipment's good condition, verification of the correct position of cameras, indication of the frequency with which recordings must be backed up for at least sixty days in accordance with Rule 2.3.8, for those with authorized supervised and strategic supervised facilities; for other cases, the recording period must be at least thirty days, as well as those responsible for their operation. These systems and all security technology infrastructure must have restricted access. Response: Explanatory Notes: Mention the documented procedure indicating the functioning of the external central alarm system or sensors, and if applicable, describe the following points: a) Indicate if doors and windows have alarm sensors, as well as the areas where motion sensors are available. b) Procedure to follow in case an alarm is activated. c) Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use.
Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensuring you include the following points: a) Indicate the number of security cameras installed in the alarm, closed-circuit television, and video surveillance systems, and their location by area (detail if it covers loading and unloading zones, including entry and exit points of the facilities, to cover the movement of vehicles and individuals, and where the inspection mentioned in sub-standard 7.2 is carried out). Attach a layout or map of the security camera distribution. b) Indicate the location of the alarm, closed-circuit television, and video surveillance systems and security technologies, where the monitors are located, who reviews them, as well as operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Periodic and random reviews of recordings must be conducted. Indicate how they are reviewed (random, weekly, special events, restricted areas, etc.), who the designated personnel are, and how management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept (must be at least one month). e) Alarm, closed-circuit television, and video surveillance systems and security technologies must have an alternative power source that allows them to continue functioning in case of unexpected loss of direct power. Therefore, indicate if the closed-circuit television, video surveillance, and security technology systems are backed up by an electrical power plant or some other mechanism to supply electricity, guaranteeing their operation. These systems should have an alarm/notification function indicating a failure in operation and/or recording; indicate if your systems have this function.
f) Indicate if, in addition to alarm, closed-circuit television, and video surveillance systems, you use any other type of technology to strengthen the security measures already in place. g) Describe the procedure implemented to regularly test and inspect alarm, closed-circuit television, and video surveillance systems and security technologies and ensure their proper functioning. The results of the inspections and functional tests must be documented, as well as necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. h) Indicate if the provider of the alarm, closed-circuit television, and video surveillance systems has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security personnel. The courier and package company must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and goods during their transport, handling, and storage within the company, as well as for controlling the entry and exit of all persons to the premises. Security personnel must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the facility. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution. Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel and ensure you include the following points: a) Indicate the number of security personnel working in the company. b) Indicate the positions and/or functions of the personnel and operating hours. c) In case of hiring an external service, provide general data of the company (Tax ID/RFC, legal name, address), and specify the number of personnel employed, operational details, records, and reports they use to perform their functions. d) In case of having armed personnel, describe the procedure for the control and storage of weapons.
3.2 Employee identification. Management or the company's security personnel must properly control the delivery and return of badges, ID cards, and/or employee identification credentials. Procedures for the delivery, return, and change of access devices (for example, keys, badges, and/or proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: a) Identification mechanisms (badge and/or photo ID, biometrics, proximity cards, etc.). b) Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable). c) Indicate how personnel hired by a business partner, working within the facilities (contractors, subcontractors, in-house services, personnel from cargo handling companies, etc.) are identified. The procedure must also describe how the company delivers, changes, and withdraws employee identification and access controls, and ensure you include the areas responsible for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for the control of identifications.
3.3 Visitor and supplier identification. To access the facilities, visitors and suppliers must present official identification with a photo for documentation purposes upon arrival, and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by company personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented. Response: Explanatory Notes: Describe the procedure for visitor and supplier access control, ensuring you include the following points: a) Indicate what records are kept (personal forms for each visit, logbooks, among others). b) The visitor and supplier record must include the following:
3.4 Procedure for identification and removal of unauthorized persons or vehicles. The courier and package company must have documented procedures specifying how to identify, confront, or report unauthorized or identified persons and/or vehicles; this procedure must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: a) Responsible personnel. b) Designate a person or area responsible for being informed of security incidents. c) Instructions for confronting and addressing unidentified personnel. d) Indicate in which cases the corresponding authorities must be notified. e) How security incidents are recorded and the measures adopted in each case.
3.5 Courier and package deliveries. Courier and package deliveries intended for company personnel must be examined upon arrival and departure, before being distributed to the corresponding areas and destinations. Likewise, the company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages, ensuring you include the following: a) Personnel in charge of carrying out the procedure. b) Indicate how the personnel or service provider of the courier and package service is identified (indicate if an additional procedure to the supplier access procedure is required). c) Indicate how the review of courier and/or packages is carried out, what mechanism is used, the records kept, and if applicable, incidents detected. d) Describe the characteristics or elements to determine what courier and/or packages are suspicious. e) Indicate what action is taken in case of detecting suspicious courier and/or packages.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, or renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of business partners must include indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses. If the investigation and/or evaluation of any business partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, if applicable, notify its security specialist or contact of the Authorized Economic Operator Program and the corresponding authority about its suspicions. Response: Explanatory Notes: Attach the information collected for the selection and contracting of new business partners and monitoring of partners already working with them; this comprises any type of commercial relationship your company has with them, and ensure you include the following points: a) What information is required from your business partner. b) What aspects are reviewed and investigated. c) Indicators to identify clients or suppliers that may not be legitimate (payments above standard rate, in cash; having little knowledge of the merchandise to be sent; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to indicating all those alerts to determine that a business partner is not reliable, thus conducting a deeper investigation and evaluating whether to work with them. d) Indicate if you maintain a physical or electronic file for each of your business partners, as well as the information it must contain. e) Indicate how the services of your business partner are evaluated and what points you review.
The file must include at least the following: a) Company data (name, Tax ID/RFC, activity, etc.). b) Legal representative data. c) Proof of address. d) Commercial references (if applicable). e) Contracts, agreements, and/or confidentiality agreements, security policies. f) If applicable, certificate or certification number in the security programs to which they belong.
4.2 Security requirements. The courier and package company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those business partners that intervene in its supply chain, such as: the services it provides as courier and package, as well as service providers such as cleaning, security, personnel hiring, installation and maintenance of alarm, closed-circuit television, and video surveillance systems, IT systems and technology providers, high-security seal providers, providers of loading, unloading, storage, and cargo handling services, contractors, airlines, among others. The requirements must be based on the Courier and Package Profile established by AGACE, or in case it exists, the specific Profile for each actor in the supply chain corresponding to them. The courier and package company must request from its business partners documentation that accredits and proves that they comply with the minimum security standards established in this Courier and Package Profile, either through a written statement issued by the legal representative of the partner, agreements or contractual clauses, or backup with documentation supporting compliance with the requirements established in another Authorized Economic Operator Program. Likewise, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its business partners, based on their activity within the supply chain. In the case of the company's business partners that provide their services within the facilities, they must be obligated to comply with these supply chain security requirements. Response: Explanatory Notes: Describe the procedure indicating how you carry out the identification of business partners that require compliance with minimum security standards. Ensure you include the following points: a) A register of business partners that must comply with security requirements, and mention what type of providers these are (transporters, warehouses, security companies, customs brokers, companies authorized to provide loading, unloading, and cargo handling services, etc.). b) Indicate in what documentary form (agreements, accords, contractual clauses and/or addenda) you ensure that your business partners comply with security requirements.
c) Indicate whether there are agreements, contracts, contractual clauses, and/or addenda regarding the implementation of security measures with your service providers within your company, such as customs brokers, private security guards, cleaning services, gardening, cafeteria, maintenance, Information Technology providers, etc.
d) Indicate whether you have business partners to whom you require membership in a supply chain security program, whether certified by a foreign authority or the private sector (for example: CTPAT, or any other World Customs Organization Authorized Economic Operator Program), as well as the information and documentation requested of them.
4.3 Commercial partner reviews. The courier and package company, through the Security Committee, must conduct periodic and risk-derived evaluations of the processes and facilities of business associates based on a risk analysis, to ensure they meet the minimum security standards required by the company based on the Authorized Economic Operator Program. It must maintain records of these evaluations, allowing verification that processes and security measures are being executed, as well as the corresponding follow-up.
When inconsistencies are found, the company must communicate this to its partner or supplier and provide a justified period to address the identified observations or areas for improvement; otherwise, it must take necessary measures to sanction them.
Conducting security evaluations of commercial partners is important to ensure that a solid security program exists and functions correctly. Therefore, in addition to a documented procedure, there must be a program or schedule for the execution of these security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company is unaware of whether the processes and facilities of its commercial partners are functioning correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure for conducting evaluations to verify the requirements (processes and facilities) of your commercial partners. Ensure you include the following points:
a) The frequency with which visits are made to the commercial partner (this must be at least once a year and derived from risk situations). b) Program or schedule for the execution of security reviews. c) Record or report of the verification and, if applicable, the corresponding follow-up. d) The verification format(s) must be duly completed, including the date, name, and position of those participating in the review, signatures, etc. e) Indicate what action measures are taken if commercial partners do not comply with the established security requirements.
f) If you have commercial partners with CTPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed, how it is recorded, and the actions taken if it is detected that they are suspended and/or cancelled in accordance with what is established in your procedure.
The procedure must include: a) Frequency of visits; b) Security review points; c) Preparation of reports; d) Feedback and agreements with the commercial partner; e) Follow-up on agreements; f) Measures in case of detecting non-compliance with requirements; g) Record of evaluations. h) Area or person responsible for carrying out this procedure.
5.1 Process Mapping. The courier and package company must have a map that shows step-by-step the logistical process of the flow of foreign trade merchandise and the required documentation through its international supply chain.
The company must take into account and include within its mapping all parties involved in its supply chain, including those that handle import and export documentation, such as customs brokers, others that may not handle the cargo directly but may have operational control such as carriers, freight service providers, cargo handling, unloading, storage, and maneuvering services, and airlines. If any part of the transport is subcontracted within its supply chain, it is essential that it be considered within its risk analysis and process mapping, as the more direct and indirect suppliers there are, the greater the risk involved.
Response: Explanatory Notes: Attach the document where you illustrate and describe the process mapping through which your import and export merchandise passes, from the point of origin to its destination, in order to have clearly identified each of the steps involving the receipt, storage, handling, custody, and delivery of courier and package cargo.
The process mapping must include the names (RFC and Legal Name) of the companies providing services in your logistics chain. This mapping must contain at least the following aspects:
a) Collection, delivery, and/or receipt of foreign trade merchandise at the distribution and/or collection center(s).
b) Security in the transfer of merchandise to a fiscalized or supervised facility:
c) Security in storage and/or distribution in a fiscalized or supervised facility. d) Security of process during customs clearance. e) Security in international transport (air, land, sea, or multimodal). f) Security in customs clearance and/or deconsolidation in the destination country. g) Delivery to final destination.
5.2 Warehouses and Distribution Centers. If the courier and package company has external warehouses and/or distribution centers registered under the same RFC, they must be subject to the provisions of this document according to their characteristics, in order to maintain integrity in its supply chain.
Likewise, indicate if you have commercial partners that provide any warehouse, distribution center, or other services within your facilities, which must at all times comply with the minimum security standards established by the company itself.
Response: Explanatory Notes: According to your logistical process mapping, if foreign trade merchandise is transferred or moved to another warehouse and/or alternative distribution center different from the one operated by the courier and package company, you must indicate if they are registered under your RFC, providing their general data (Name and address) and briefly explaining what activity is carried out in that or those facilities (Cross Dock, temporary warehouse, etc.).
Likewise, indicate if these belong to the company or is a service contracted through a third party and are part of a shareholder group. In this case, according to the supplier selection criteria mentioned in the Commercial Partners section of this document, indicate how you ensure compliance with minimum security requirements (warehouses administered by a third party are not required to present a Courier and Package Profile).
Facilities that have a concession or authorization for a Fiscalized Facility or Strategic Fiscalized Facility, registered under your RFC, must fill out the Profile for the corresponding modality and category for each authorized facility.
5.3 Cargo Delivery and Receipt. The courier and package company must guarantee the supervision of the identification of operators of its own or subcontracted transport means that carry out the collection, delivery, or receipt of foreign trade merchandise within or outside its facilities, warehouses, and/or distribution centers.
Likewise, it must designate a person responsible for supervising the loading or unloading of the shipment, even in accordance with instructions received from clients for its handling and transfer. On the other hand, it must supervise, inspect, and verify through mechanisms, tools, or non-intrusive technology available to it, the integrity of the transport means and the foreign trade merchandise entering or leaving the courier and package company, checking the information described in the exchange lists received previously in accordance with the traffic or transport modality in question.
Likewise, it must guarantee that the driver transporting foreign trade merchandise, during delivery or receipt, has the required documentary information before undergoing customs clearance formalities and authorizing its exit.
The cargo preparation areas and the immediate surrounding areas must be inspected regularly to ensure that these areas remain free of visible contamination by pests.
During the cargo loading and unloading process, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise, or pests), and record said review (incident reports, records, reports, etc.). As evidence that the high-security seal and/or lock was placed correctly, digital photographs must be taken at the time of loading the vehicles. Whenever possible, these images should be sent electronically to the destination or delivery contact point of the merchandise for verification purposes.
Also, the personnel responsible for the shipping and/or receiving area must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on identifying common errors in export shipment documentation, with the aim of preventing these from resulting in security incidents or suspicious merchandise.
If the company has its own cargo transport, it must provide training to transport operators to review import and/or export documentation in order to identify or recognize suspicious cargo shipments, such as: a) Originating or destined to unusual places; b) Different routes; c) Cash payments; d) Unusual shipping and/or receiving practices; e) Lack of information.
Response: Explanatory Notes: Attach the documented procedure for cargo delivery and receipt, including the following: a) Inspection method at the access point to the courier and package company. b) Designation of personnel responsible for receiving the driver and merchandise upon arrival. c) Coordination of the courier and package company areas that receive exchange lists from transporters prior to their arrival and with the customs offices where customs clearance formalities are fulfilled. d) Record of the introduction to the courier and package company of merchandise with full and consolidated cargo. e) Release deadlines. f) Prior requests.
g) Services offered by the courier and package company for the movement of merchandise prior to its customs clearance. h) How it guarantees that the transport means is free of visible pest contamination; if any type of visible pest, contamination, trash, insects, grass, weeds, or hay is identified, how it is reported and what actions are taken regarding it.
Attach the documented procedure to detect and report discrepancies in the delivery or receipt of transport means carrying merchandise, and ensure it includes the following points: a) Persons responsible for carrying out the review. b) Documents to be checked. c) Areas to which the information is reported.
5.4 Cargo Tracking Procedure. The courier and package company is responsible for monitoring and supervising the integrity of foreign trade merchandise throughout the supply chain; therefore, it must have documented procedures that establish the use of technology for the tracking and supervision of activities (during collection; arrival at its cargo consolidation centers, storage, custody, and release of foreign trade merchandise), with the aim of guaranteeing compliance with customs clearance formalities, ensuring at all times to have the following information: bill of lading number and information, packing list, waybill, or other transport documents, as applicable, name and address of the consignee or sender, description, value, and origin of the merchandise, physical location in the facility, among others, in accordance with applicable regulations.
For the purposes of tracking units via land, the company must include in the aforementioned procedure the identification of predetermined routes, estimated times for collection and delivery at warehouses and/or distribution centers or collection points, if applicable, and intermediate points. Likewise, it must describe the measures in case of identifying delays on the route due to weather conditions, traffic, route changes, authority inspections, or security-related incidents.
Supervision data and records of all maneuvers in the courier and package company, as well as route histories, must be preserved for one year in case the authority and/or transporter must conduct an evaluation due to a security incident.
Response: Explanatory Notes: Attach the documented procedure to monitor internal transfers in the courier and package company of complete and/or consolidated foreign trade merchandise.
This procedure must include, among other aspects according to its operation: a) Have GPS whose external hardware is hidden and can resist attempts to remove it; indicate the type of system implemented for the units used and, if applicable, the consultation tools available to monitor the merchandise. b) Identify predetermined routes, estimated delivery times, between intermediate points and maneuvers in courier and package companies according to the transport involved. Once the time between assigned points has been determined, there must be a tracking process (route audit) and corresponding records.
There must be systems or procedures with instructions in case of a delay in the route; likewise, drivers must notify their supervisor of any significant delay on the route due to weather, traffic, accidents, mechanical failures, route changes, etc. And on its part, the company must independently verify the cause of said delay.
c) Detail if you have a means to communicate with the transporter during its transfer and if you have more than one form of communication. d) If tracking is carried out by a third party, indicate who is responsible and how it is verified that it is being carried out correctly, in accordance with the procedures the company specifies. e) If the company has its own cargo transport, GPS or equivalent technology must be used to guarantee that the trailer is also monitored and tracked. Describe how you carry out this tracking. f) GPS records or route histories must be safeguarded for security incidents and audits.
5.5 Cargo Discrepancy Report. There must be documented procedures to detect and report missing, excess, prohibited, or any other discrepancy in the delivery or receipt of merchandise collected prior to fulfilling customs clearance formalities, with the aim of having information that aids corresponding investigations by authorized consignees and, if applicable, by competent authorities. Likewise, it must describe the measures and actions to be taken in case of identifying the transfer and handling of illicit, undeclared, and prohibited merchandise or those that by their nature put user security at risk, which could occur during the following processes: receipt, delivery, warehouse for prior inspections, consolidated, de-consolidated, transport means yards, and if applicable, according to the services offered.
Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of merchandise, and ensure it includes the following points: a) Persons responsible for carrying out the review. b) Documents to be checked. c) Areas to which the information is reported.
This procedure must be applied to consolidated merchandise located in the warehouse.
5.6 Processing of Cargo Information and Documentation. The courier and package company must have documented procedures to ensure that electronic and/or documentary information used during the movement, storage, custody, maneuvers, and dispatch of cargo, as well as information received from business associates, is legible, complete, accurate, reported in real-time, and protected against changes, loss, or introduction of erroneous information.
Likewise, there must be documented procedures to corroborate that the information received from business associates is reported accurately and timely.
Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use.
Response: Explanatory Notes: Describe the procedure for processing cargo documentation, ensuring you include the following points: a) Detail how you transmit relevant information and documentation regarding the transfer and maneuvers of cargo, as well as all parties involved in the courier and package company's supply chain. Indicate if you use a specific computer control system and briefly explain its function. Likewise, detail how you validate that the provided information is legible, complete, accurate, reported in real-time, and protected against changes, loss, or introduction of erroneous information. b) The electronic information of shipments and cargo in general must include the seal and/or lock number with which the cargo was secured. c) Indicate how business associates transmit information to the courier and package company and ensure its accuracy, for example: the use of the institutional application "Consulta Remota de Pedimentos" to corroborate the payment of contributions and/or compensatory fees for exit authorization.
5.7 Inventory Management, Control of Packaging, Container, and Packing Material. The courier and package company must have documented procedures for inventory control and cargo storage; these must involve periodic reviews and audits to prove their correct management. Likewise, it must have a documented procedure for the control of packaging, container, and packing material of merchandise, which must also include the control, dissemination, and prevention procedure of visible pest contamination, in the case of using wooden packing materials (such as pallets, boxes, crates, cages, spools, dunnage, chocks, supports, or platforms) to stack, move, and protect cargo throughout its entire supply chain.
Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, among other aspects according to its operation: a) The frequency with which it carries out stock verification (periodic inventory). Indicate if there is a documented scheduled calendar to carry them out.
b) Indicate what is done in the case of surpluses and shortages in inventories. c) Specify the treatment provided for the control and handling of packaging, container, and packaging material, and, where applicable, shrinkage, waste, or leftover material, which must also include the control, dissemination, and prevention procedure for visible pest contamination, in the case of the use of wooden packaging materials (such as pallets, boxes, crates, cages, spools, dunnage, supports, or platforms) for stacking, moving, and protecting the cargo. d) This point is also focused on reducing the risk of introduction or dissemination of pests of quarantine importance to the country through packaging (imports); therefore, describe how you comply with the provisions established by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144-SEMARNAT-2017, in accordance with International Phytosanitary Measure No. 15 entitled Regulation of Wood Packaging Material Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. e) Specify how the fumigation process is carried out to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions do you take if quarantine of packaging materials is required? f) Indicate the area or person responsible for carrying out this process, as well as the documentation or certificates obtained. The applicant's procedures may include: a) Warehouse accessible only to authorized personnel. b) Frequency of inventory control. c) Control of incoming goods, transfers to other warehouses, permanent and temporary withdrawals. d) Actions taken if irregularities, discrepancies, losses, or thefts are identified. e) Treatment of deterioration or destruction of goods. f) Separation of various types of goods, for example: high value or hazardous.
6.1 Customs Clearance Management. The courier and package company must have a documented procedure that establishes the criteria for the selection of a customs broker or, where applicable, a customs representative, who, in accordance with national legislation, are authorized to promote the clearance of goods on behalf of others. Response: Explanatory Notes: Describe the selection and evaluation procedure of the customs broker or customs representative and ensure it includes the following points: a) Selection criteria. b) Evaluation methods and frequency. c) Describe the indicators with which you evaluate the service of customs brokers. Indicate the full name and the patent and/or authorization number of the customs broker or customs representative authorized to promote your foreign trade operations.
6.2 Customs Obligations. The courier and package company must have a documented procedure for the compliance of customs obligations arising from the foreign trade operations it carries out. This must include at least the following: the communication process with customs authorities when they are aware of the transfer and custody of values higher than those determined by the authority in accordance with Article 9 of the Law. The transmission of cargo manifests through the SEA (Digital Counter) and the established deadlines, in accordance with Article 38 of the Law Regulations and Rule 1.9.15.; notices in cases of destruction, loss, and decomposition of goods; the customs clearance process through the legal representative of the courier company whenever they do not exceed the determined amounts, the established exceptions, and the determination of payment of the global rate that corresponds. For cases where it provides the service of electronic pre-validation of data, establish how it complies with the obligations foreseen in Rule 1.8.2; the notices that must be sent to the authorities regarding explosive goods and firearms; the updating of data in the CAAT registry and its frequency. The processes for the return of goods when they are in deposit with customs; regarding the use of the generic RFC in case of global operations and the use of RFC for individual operations. In addition to the above, the courier and package company, if it has authorization as a Strategic Fiscalized Facility, Fiscal Deposit, or for manufacturing, transformation, or repair in a Fiscalized Facility, must have a documented procedure for the compliance of customs obligations arising from the foreign trade operations it handles. This must include at least the following: a) the annual guarantee that must be paid to the fiscal interest in accordance with the average value of the goods it handles; b) The identification of the physical space for the customs inspection carried out by customs authorities; c) the physical space designated for handling, storage, and custody services regarding goods that have become property of the federal treasury; d) the free storage and custody of goods in accordance with the regulations; e) process for the transfer of goods between warehouses; f) process to prove payment of revenues for being a fiscalized facility; g) regarding the authorization for goods to be subject to manufacturing, transformation, or repair, where applicable. On the other hand, it must include in the procedure, the communication process with consignees in case of destruction or loss of goods; guarantee the exchange of information through a simultaneous system containing the data indicated in Rule 2.3.8 and establish protocols related to the treatment, communication, storage, and custody of foreign trade goods under the internal transit regime. Response: Explanatory Notes: Attach the procedure to comply with your customs obligations.
6.3 Customs Verification. The courier and package company, in order to guarantee the compliance of the information of the operations for the customs clearance of foreign trade goods, as well as to verify the truthfulness of the information declared to the competent authorities, must have documented procedures to verify that the customs declarations it receives for its release processing from the company match what is registered in SAAI Web and, where applicable, report to the customs authority any discrepancy in said information. The company, likewise, must have a procedure for the filing of the corresponding release records. Response: Explanatory Notes: Attach the established procedure to verify the information registered in SAAI Web, and cross-check that contributions and/or compensatory quotas had been paid prior to the release of the shipments to be subject to the formalities of customs clearance.
7.1 Use of seals and/or padlocks. The courier and package company, where applicable, must identify the means of transport of its own or subcontracted cargo that transport foreign trade goods that may be: maritime, air, national land, cross-border, railway, and/or multimodal that are subject to the placement of seals and/or padlocks that comply with or exceed the ISO 17712 Standard with the aim of guaranteeing at all times the integrity of the cargo. For this reason, as one of the security mechanisms, the fiscalized facility, where applicable, must use high-security padlocks or seals that comply with or exceed the ISO 17712 Standard on all containers and trailers loaded for foreign trade and maintain their integrity until delivery at the final destination. For this, the facility must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when they are opened by any authority. In the event of such an inspection, drivers must notify and register any anomaly or unusual structural modification found in the means of transport derived from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to the commercial partners involved in the supply chain, and the investigation of the security incident; these must be notified to security personnel, commercial partners who may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program. Likewise, it is necessary to have a documented procedure for their administration that includes control, assignment, safeguarding, handling of discrepancies, and destruction of seals and padlocks (the latter is mandatory whenever seals are broken in your facilities). Regarding the provider of the seals and/or padlocks, it must be demonstrated how these comply with the ISO 17712 Standard. The company's management or a security supervisor must carry out periodic and documented audits of the high-security seals and/or padlocks; these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-check with inventory records and shipping documents. Also, the supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and Instruments of International Traffic to corroborate that the information is correct.
For this case, the courier and package company must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or padlocks on the means of transport that transport foreign trade goods in accordance with its logistics process and in those traffics that require it due to their high probability of occurrence and impact of the identified risk. In it, it must evidence controls that allow accrediting that it supervises the portability of seals and/or padlocks derived from entries or exits of the strategic fiscalized facility in the means of transport. In all cases, it must use the VVTT inspection method to mitigate improper manipulations in accordance with the following: a) V- View the seal and lock mechanisms of the container. b) V- Verify the seal number. c) T- Pull the seal to ensure it is correctly placed. d) T- Twist and turn the seal to ensure. Response: Explanatory Notes: List, according to your risk analysis and logistics process, the means of transport that are subject to the placement of high-security seals and/or padlocks. Attach the documented procedure for the placement and review of seals and/or padlocks on the means of transport that transport foreign trade goods. This must include, among other aspects according to your operation: a) Verify that the seal or padlock is intact and determine if there is evidence of improper manipulation. b) In the event of using high-security padlocks, of the bottle type, use the VVTT inspection method.
e) Indicate how you assign and replace high-security padlocks, in the case of maneuvers such as prior inspection, replacement, among others. Where applicable, attach the documented procedure for the control and handling of seals and/or padlocks; this must include, among other aspects according to your operation: a) What type of seals and/or padlocks you use in your operations (foreign trade, transit, storage, etc.). b) Who has access and how padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (record of seals used, as well as the receipt of new seals and/or padlocks. c) Describe how the company's management or the security supervisor participates in the audits of high-security seals and/or padlocks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how the supervisors of the shipping area and/or warehouse managers verify the seal numbers used in the means of transport and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). d) How discrepancies in seal and/or padlock numbers are addressed. e) Indicate who the supplier(s) is/are and how it proves that the specifications of the seals and/or padlocks comply with the ISO 17712 Standard (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO). All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of means of transport, containers, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of the means of transport, container, train cars, trailers, and/or semi-trailers used as Instruments of International Traffic, that enter or leave the courier and package company in accordance with their nature, even the reliability of the door lock mechanisms, with the aim of identifying natural or hidden compartments. The inspections of the means of transport must be systematic and carried out upon entry and exit from the company, and where applicable, at the cargo loading point, using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by closed-circuit television and video surveillance systems; said system must cover the inspection process in its entirety. The documented procedure for its inspection must include, by way of example and not limitation, the following review points: Means of Transport Trailers, Train Cars, Semi-trailers, and Containers
c) The security review points for means of transport, trailers, semi-trailers, containers, railway transportation, and/or multimodal, both for security and those for quality and agricultural inspections with the aim of looking for visible pests. d) Instructions for the driver to ensure that the cab is clean and free of garbage before crossing. Attach the established format for the inspection of means of transport or cargo vehicles, containers, trailers, and/or semi-trailers. If you use other types of cargo vehicles for the transport of your goods (vans, pickups, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points. Likewise, the security and agricultural inspection format must include the following information: a) Date of inspection; b) Time of inspection; c) Vehicle license plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected; and, f) Name and signature of the employee who performs the inspection and of the supervisor. The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation. The documentation must be kept for one year for an investigation in the event of any security incident, as well as to demonstrate continuous compliance with these inspection requirements. Additionally, and based on the risk analysis, the courier and package company should carry out periodic random reviews of cargo vehicles, after the transport personnel has carried out security inspections to verify that they have been carried out correctly, counter internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the means of transport may be susceptible to contamination.
7.3 Storage of vehicles, means of transport, containers, train cars, trailers, and semi-trailers. In the event that the means of transport, containers, trailers, and/or semi-trailers intended to transport foreign trade goods are empty and must be stored in parking areas, they must be secured with a padlock and/or indicative seal, or, in their case, in a secure area that is guarded and/or monitored. When it is necessary to store or overnight any loaded container, trailer, and/or semi-trailer, it must be located in a secure area with physical barriers and monitored by alarm systems, closed-circuit television, and video surveillance to prevent unauthorized access and manipulation of the cargo; therefore, it must be closed with a high-security padlock in accordance with ISO 17712 Standard. When the cargo is stored overnight or for an extended period, measures must be taken to secure the cargo against unauthorized access. Response: Explanatory Notes: Indicate whether the company stores containers, trailers, and/or semi-trailers for subsequent dispatch, or, in their case, those that are empty, and how it maintains their integrity within its facilities. a) In the event of using padlocks and/or seals, indicate what type is used. b) In the event of using any containers, trailers, and/or semi-trailers as storage for raw materials and/or any other type of goods, indicate how it maintains their integrity and security. 8. Personnel Security. The courier and package company must have documented procedures for the registration and evaluation of individuals seeking employment within the courier and package company, and establish methods to conduct periodic verifications of current employees. Furthermore, there must be continuous training programs for personnel that disseminate the courier and package company's security policies, as well as the consequences and actions to be considered in the event of any security breach or incident. 8.1 Verification of work history. The courier and package company must have documented procedures to investigate and verify the information stated in the curriculum vitae, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either independently or through an external company. Similarly, for positions that require it due to their sensitivity and affect the security of shipments, in accordance with the previously conducted risk analysis, stricter requirements for hiring must be considered, which must be carried out periodically. Regarding personnel already working in the company, periodic investigations must be conducted based on the functions and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for hiring personnel, and ensure to include the following: a) Requirements and documentation demanded. b) Tests and exams requested. Indicate the areas and/or critical positions identified as risky, according to your analysis, and indicate the following: a) Indicate if there are additional requirements for specific areas and/or work positions, such as criminal records (if legislation and company policies allow), socioeconomic studies, clinical studies, toxicological (drug use) studies, etc. In their case, indicate the positions or work areas where they are required and with what frequency they are carried out. b) Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. In the event of hiring a service agency for personnel hiring, indicate if it has documented procedures for personnel hiring and how it ensures compliance with the same. Briefly explain what they consist of. The procedures for personnel hiring and contractors may include: a) Exhaustive investigations of the work and personal backgrounds of new employees. b) Confidentiality and liability clauses in employee contracts. c) Specific requirements for critical positions. d) In their case, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. The company may consider the results of background checks on candidates, as permitted by current legislation, to make hiring decisions. Background checks are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Procedure for personnel dismissal. There must be documented procedures for personnel dismissal, which include the delivery of identification and any other item provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include the deactivation in those computer systems and access systems, among others that may exist. Response: Explanatory Notes: Describe the procedure for personnel dismissal and ensure to include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the delivery of identification, uniforms, keys, and other equipment is carried out and confirmed. c) Indicate the control, record, and/or format in which the delivery of material and deactivation in computer systems (in their case, attach) is identified and ensured. d) Specify the type of records of personnel who ended their employment relationship with the company, so that in case it was for security reasons, their service providers and/or business associates are warned. 8.3 Personnel administration. The courier and package company must maintain an updated system, control, or database of active employees. Likewise, it must carry out and maintain updated records of affiliation to social security institutions and other legal labor records. In the event that the company has personnel hired by its commercial partners and working within the facilities, it must ensure that they comply with the requirements established for the rest of its employees. Response: Explanatory Notes: Indicate if the courier and package company has an updated system, control, or database, both for personnel hired directly and that hired through a service provider company, and ensure it includes, among other things, the following points: a) Full name. b) Updated photograph at least every five years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). d) Affiliation. e) Work history. f) Diseases. g) Medical exams. h) Training. i) Psychometric exams. j) Toxicological exams. k) Results of periodic evaluations. l) Observations. This personnel must be hired in accordance with current labor laws and regulations.
Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how it backs up and ensures the security of its information, in addition to protecting it from possible losses. Ensure to include the following points: a) Specify the frequency with which backups are carried out. b) Who has access to them, and who authorizes the recovery of information. c) Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. d) Mention if, to carry out this type of tests or vulnerability scans, it does so through software, a third party, or provider, and, in their case, indicate the name or corporate name. e) In the event of finding vulnerabilities, describe the corrective actions that must be implemented. f) Indicate if it shares information about cybersecurity threats with its commercial partners participating in its supply chain (for example: press releases, bulletins, emails, etc.). g) Systems must be protected by passwords and must be modified frequently; therefore, indicate the procedure for changing them. h) Specify if there are information security policies for their protection. i) There must be a system or software to detect, identify the abuse, intrusion, or access of unauthorized persons to its systems and/or information technology data, as well as the abuse of policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in the event of the detection of any violation of Information Technology security systems and policies.
Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In the event of allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely. Specify if commercial partners have access to the company's computer systems. In their case, indicate what programs they use and how they ensure control over access to them. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the courier and package company's information must also include: a) How and for how long the data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in case of incident and how to recover the information. c) Frequency and location of backups and archived information. d) If backups are stored in sites alternative to the facilities where the data processing center is located. e) Tests of the validity of data recovery from backups. The procedures regarding the protection of the courier and package company's information must also include: a) An updated and documented policy for the protection of computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. b) Detail if it operates with multiple systems (headquarters/sites) and how such systems are controlled. c) Who is responsible for the protection of the computer system (responsibility should not be limited to one person but to several so that each can control the actions of the rest).
d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. For the above, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to personnel authorized to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, in its case, report that access to confidential systems is based on job requirements. e) Indicate the elements or format that passwords for accessing Information Technology systems and computer equipment must have, frequency of changes, if there are other authentication methods, and who or what area provides those passwords. f) Indicate the name of the "firewall" and anti-virus used (include licensing-related information), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit technological products or those with incorrect licenses (software and hardware). All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be disposed of, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage. g) In the event of personnel dismissal, access to computer equipment, telecommunications, and the network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. h) Measures planned to handle incidents in case the system is compromised.
10.1 Training and awareness on threats. The courier and package company must have a training and awareness program on security policies in the supply chain directed to all its employees, and additionally, make available informational material regarding the established procedures in the company to identify a situation that threatens its security and know how to report it. Similarly, specific training must be offered according to their functions to help employees maintain cargo integrity, perform inspections of containers, trailers, and/or semi-trailers for agricultural and security purposes, receive and inspect courier and package services, prevent operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and report internal conspiracies, protect access controls, as well as training regarding smuggling, cargo theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the company's procedures. In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures, and standards (theft, data leak, hacking, and/or information kidnapping), including access to computing equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodically maintain update programs. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of attendees, the topics taught, as well as measures to verify that the training provided met all training objectives.
Response: Explanatory Notes: Must have a training program on security and prevention of security incidents in the supply chain for all employees working for the company (administrative, operational, direct, indirect). Briefly explain what it consists of, and ensure to include the following: a) Brief description of the topics taught in the program. b) When they are taught (onboarding, specific periods, resulting from audits, security incidents, etc.). c) Frequency of training, as well as updates and reinforcement. d) Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of attendees, the topics taught, as well as measures to verify that the training provided met all objectives of the same. e) Explain how employee participation in security matters is encouraged. Training to perform inspections of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments. b) Smuggling hidden in natural compartments. c) Signs of pest contamination. d) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit. e) Agricultural review training must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with International Phytosanitary Measures Standard No. 15, titled Regulation of Wood Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations, and the identification of infested wood.
10.2 Awareness for transport medium operators. The courier and package company must inform the operators of the transport means it uses for the transfer of goods originating from or destined for foreign trade, regarding security policies concerning agricultural and security inspection procedures of cargo loading and unloading transport means, incident management, lock changes in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of transport means must be trained to inspect cargo vehicles for such purposes. In the case where the transport service is provided by a business partner, the company must ensure that operators know all established security policies and procedures.
Response: Explanatory Notes: Describe the dissemination program on security in the supply chain focused on transport medium operators and ensure to include the following: a) Indicate how this dissemination is carried out. b) Point out the topics covered. c) In case of using the services of a business partner for the transfer of goods, indicate how operators are informed of the company's security policies and procedures. d) Indicate how participation in supply chain security training of transport medium operators is documented (videos, attendance lists, brochures, etc.). The topics that must be included, in an illustrative but not exhaustive manner, are: a) Access and security policies at facilities. b) Delivery-receipt of goods (including suspicious cargo shipments). c) Confidentiality of cargo information. d) Transfer instructions. e) Accident and emergency reports. f) Instructions for placing high-security locks and/or seals in case of inspection by other authorities, as well as the control and use of high-security seals and locks in transit (placement of a new one, inspection after any authorized stop, etc.). g) Installation and testing of security alarms and unit tracking, where applicable. h) Identification of authorized formats and documents to be used. i) Signs of hidden compartments. j) Smuggling hidden in natural compartments. k) Signs of pest contamination. l) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
11.1 Reporting of anomalies and/or suspicious activities. In the event of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with its logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of such anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as the mechanisms to anonymously inform about security-related problems, ensure to include the following: a) Who is responsible for reporting incidents. b) Detail how it determines and identifies with which authority to communicate in different scenarios or presumption of suspicious activities. c) Mention if it keeps a record of reporting these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, as well as corrective actions to prevent them from occurring again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that require it. This information must include the documentation generated to carry out the foreign trade operation of the affected goods, which will allow identifying each of the processes the goods went through, up to the point where the incidence was detected, and allowing recognition of the supply chain's vulnerability.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any incident occurring, and ensure to include the following: a) Responsible for carrying out the investigation. b) Documentation that integrates the security incident investigation file. The documents to be included in the file resulting from the investigation, in an illustrative but not exhaustive manner, may be: a) General information of the shipment, service order. b) Transport request; confirmation of transport medium; identification of transport operator (access records, exit records, security inspection records, etc.). c) Transport medium inspection formats; exit orders; records of collection, delivery, and receipt of foreign trade goods. d) Videotapes from closed-circuit television and video surveillance systems. e) Documentation generated for the carrier (bill of lading, waybill, instruction sheet). f) Documentation generated for business partners (service order, description of goods, proformas, CFDI or equivalent documents, etc.). g) Documentation generated by business partners and customs authorities. h) Unit tracking and monitoring report (GPS tracking).
E7. Profile of the Authorized Customs Warehouse. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data provided will replace the data provided when requesting authorization. General Information The objective of this Profile is to ensure that authorized customs warehouses have security practices and processes implemented at their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products. Authorized customs warehouses interested in obtaining the authorization referred to in Rule 7.1.5, must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards, the application of a risk analysis culture supported by decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the company itself. What is established in this Profile must be accredited independently of the requirements and provisions established for the control, surveillance, access routes, infrastructure, equipment, and security of foreign trade goods established by ANAM, to grant the Authorized Customs Warehouse authorization, and compliance with what coincides with what is established in this Profile can be proven. Filling Instructions:
You must fill out an Authorized Customs Warehouse Profile for each of the facilities that have a concession or authorization as an authorized customs warehouse. The number of Profiles presented must coincide with the facilities that have a concession or authorization to provide handling, storage, and custody services for foreign trade goods in accordance with articles 14 and 14-A of the Law, manifested in your application for registration as a certified business partner under the authorized customs warehouse modality, as well as indicating all domiciles registered with the RFC.
In each sub-standard, the authorized customs warehouse must detail how it complies with or exceeds what is established in each of the sections as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Description of the standard 1.1 Sub-standard. Description of the sub-standard Response. Explanatory Notes Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards, therefore you must attach the procedures in Spanish that are required, if applicable, or provide a detailed explanation of what is requested in the Response field. The section regarding Explanatory Notes is intended to be used as a guide regarding the points that must be included in the Response or in the attached procedures, as appropriate, of each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once this Authorized Customs Warehouse Profile is answered, you must attach it to the Application for registration in the Certified Business Partner Registry referred to in the first paragraph of Rule 7.1.5, fraction V, subsection b. For the purpose of verifying what is stated in the previous paragraph, the SAT through the AGACE may carry out an inspection of the installation indicated here, with the exclusive purpose of verifying what is stated in this document.
Any incomplete Authorized Customs Warehouse Profile will not be processed.
Any question related to the Application for registration and the Authorized Customs Warehouse Profile should be directed to the contacts appearing on the SAT Portal.
In the event of being authorized as a Certified Business Partner, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and as a result changes or modifications are required in the information stated and provided in this Authorized Customs Warehouse Profile to the authority in accordance with what is established in Rule 7.2.1, fourth paragraph, fractions I, II, and VII.
When, as a result of the inspection visit, non-compliance with minimum security standards results, the applicant may remedy them before the issuance of the resolution established in Rule 7.1.6, for which they will have a maximum period of three months counted from the notification of the indicated non-compliances. Installation Data An Authorized Customs Warehouse Profile must be filled out for each of the installations that belong to and operate under the concession or authorization of authorized customs warehouse and that provide handling, storage, and custody services for foreign trade goods. Installation Information Profile Number of the Authorized Customs Warehouse: of RFC Name and/or Business Name: Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of the installation (years of operation): Activity carried out at the installation: Preponderant products handled in the authorized customs warehouse: (As applicable) Avg. No. of monthly shipments (EXP): Avg. No. of monthly shipments (IMP): Total number of employees at this installation: Installation Surface Area (M2):
Certifications in security programs: (indicate if this facility holds a certification from any of the following programs) CTPAT. Yes No Level: Pre-Applicant: Applicant: Certified: Certified/ Validated: CTPAT. Account number (8 digits): Date of last visit to this facility: Authorized Economic Operator from other countries (AEO) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration: Certifications: (indicate if you hold certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The supervised facility must establish measures to identify, analyze, and mitigate security risks that could result in alterations of foreign trade merchandise during its handling, guarding, and custody in its supply chain and facilities. It must develop a written process to determine risks based on its organization's model (e.g., type of merchandise, volume, clients, routes, information leakage, potential threats, etc.), so that it allows it to implement and maintain appropriate security measures. Based on the above, the company must also have a written process based on its risk analysis to select new business partners and monitor partners with whom it is already working. This procedure must be updated at least once a year, so that it allows permanent identification of new threats or risks considered in the operation and supply chain, resulting from any incident or originating from changes in initial conditions, as well as to identify whether policies, procedures, control mechanisms, and security are being complied with. It is important to note that the Supervised Facility's Security Committee must participate in the drafting and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate what sources of information are used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the facility's installations, which must contemplate the risk assessment and management process of the facility, including the following points: a) State the frequency with which it reviews and, if applicable, updates the procedure and its risk matrix. b) Indicate what aspects and/or areas of the facility are incorporated into the risk analysis. c) Describe the methodology used to determine a risk analysis. d) Mention who are the responsible parties for updating the facility's risk analysis. Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the risk assessment and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Indicate the risks identified in the installation and in its supply chain or logistics. c) Risk analysis of causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low. d) Risk evaluation (decision-making to determine the risks to be treated and priority for implementing the treatment). e) Risk treatment (application of alternatives to change the probability of risks occurring). Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). a) Indicate the review and/or update period of the risk analysis results. It is suggested to use Risk Administration, management, and evaluation techniques in accordance with international standards ISO 31000, ISO 31010, and ISO 28000 that, according to its business model, it must implement.
1.2 Security Policies. The supervised facility must have a policy oriented towards preventing, securing, and recognizing threats to the security of the supply chain and facility installations, such as drug trafficking, money laundering, arms trafficking, human smuggling, prohibited goods, and acts of terrorism. These policies must be reflected in the corresponding procedures and/or manuals. To promote a security culture, supervised facilities must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. Senior officials or executives of the supervised facility who must endorse and sign the security policy may include the facility president, chief executive officer, general manager, security director, or personnel with equivalent rank with authority to make decisions.
Response: Explanatory Notes: State the security policy oriented towards preventing, securing, and recognizing threats in the supply chain and installations of the supervised facility, indicate who is the responsible for its review, signature, and dissemination to employees, as well as the frequency with which it is carried out its update. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the supervised facility, including the facility's website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the initial and reinforcement training of the company.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year, under the guidelines of a documented procedure that allows evaluating all processes regarding supply chain security and its facilities in a more critical and in-depth manner, as well as guaranteeing that employees follow the facility's security procedures. Audits must be carried out by the facility's Security Committee; a documented procedure must be established, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, risk, business model, and variations between installations. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. Senior management must review the audit results, analyze causes, and undertake required corrective or preventive actions. The audit process must guarantee that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to the fact that the Supervised Facility's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain, ensure you include the following points: a) State how the facility carries out the scheduling or calendarization to perform an internal audit, in matters of security in the supply chain. b) Indicate who participates in them, and the records that are generated, as well as the frequency with which they are carried out. c) Indicate how the management of the supervised facility verifies the result of the audits in matters of security and how it performs and/or implements actions preventive, corrective, and improvement, in addition to the follow-up and closure of the same. d) The formats used during internal audits must be duly filled out, and through them, evidence that the procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans related to Supply Chain Security. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity in case a situation affects the normal development of activities and foreign trade operations in the installations and during the transfer, handling, storage, and custody of foreign trade merchandise according to its logistics process in the supply chain. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a bomb threat, the detection of suspicious packages, power outages, theft and/or damage to merchandise, threats or extortion, among others). Such plans must be communicated to personnel through periodic training, as well as conducting tests, practical exercises, or annual drills of the contingency and emergency plans to verify their effectiveness, from which it must maintain a duly filled out and signed record (for example: result reports, minutes, or reports, which must be backed by video recordings, photographs, etc.), demonstrating their execution. The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in case of an emergency or security situation that affects the normal development of foreign trade activities of the supervised facility. This procedure must include, in an enumerative but not limiting manner, the following: a) What situations it contemplates. Describing the plan of action and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. b) What mechanisms it uses to guarantee that the business continuity plan is effective.
c) Contemplate the scheduling and execution of tests, practical exercises, and annual drills and how they are documented (for example: result reports, minutes or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution).
2.1 Installations. Installations must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of structures, and in case an irregularity has been detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal routes, and the location of buildings must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others), and indicate how the review and maintenance of the integrity of structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damages to the installations. Attach a general distribution or architectural plan, where the limits of the installations, access routes, emergency exits, traffic flow, the location can be identified of buildings, critical areas, parking lots, and boundaries.
2.2 Accesses at Doors and Booths. The entrance or exit doors of personnel and/or vehicles of the company's installations must be attended, controlled, watched, and supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the installations, as well as the operating hours of each one, and indicate how they are monitored (in case of having assigned surveillance personnel, indicate the quantity). Detail if there are doors and/or accesses blocked, or permanently closed and their location. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the perimeters of the supervised facility's installations, and particularly, the areas for storage, custody, and warehousing of foreign trade merchandise, high value, hazardous, in accordance with applicable regulations, areas with restricted access, and others determined according to its risk analysis with the object of preventing unauthorized entries. These must be inspected regularly and keep a record of the review with the purpose of ensuring their integrity and preventing or identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks. The storage, high value, hazardous, and/or restricted access areas must be clearly identified and monitored to prevent unauthorized entries.
Response: Explanatory Notes: Describe the type of peripheral barrier and/or fences with which the installation has, ensure you include the following points: a) Specify which areas it segregates in the installation by being considered critical and/or sensitive. b) State their characteristics (material, dimensions, etc.). c) In case of not having fences, justify detailedly the reason. d) Frequency with which the integrity of the perimeter fences is verified, and the records that are carried out, with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible. e) Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages. Describe how the cargo destined for foreign countries, hazardous material, and high value cargo is segregated; ensure you include the following points: a) Indicate how it separates national merchandise and foreign trade merchandise, and if it is additionally identified (For example: different packaging; labels; packaging, among others). b) Identify and state the restricted access areas (hazardous goods, high value, confidential, etc.). The procedure for inspecting perimeter fences could include: a) Personnel responsible for carrying out the process. b) How and with what frequency the inspections of fences, perimeter fences and/or peripheral barriers and buildings are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that repairs and/or modifications comply with the technical specifications and necessary security requirements.
2.4 Parking Lots. Access to the installations' parking lots must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas.
Response: Explanatory Notes: Describe the procedure for the control and monitoring of the parking lots, ensure you include the following points: a) Responsible for controlling and monitoring access to the parking lots. b) Identification of the parking lots (specify if the visitor parking is separated from the storage and merchandise handling areas). c) How the entry and exit control of vehicles to the installations is carried out. Indicate the records that are made for parking control, the existing control mechanisms (for example: ticket stubs, card readers, badges, etc.), how they are assigned and the area responsible for doing so. d) Policies or mechanisms to not allow the entry of private vehicles to the storage and merchandise handling areas.
2.5 Key and Lock Device Control. Windows, doors, and inner and outer fences, according to your risk analysis, must be secured with locking devices. The company must have a documented procedure for the handling and control of keys and/or locking devices for inner areas that have been considered critical. Likewise, a record must be kept and responsibility letters signed by persons who have keys or authorized accesses according to their level of responsibility and work within their work area.
Response: Explanatory Notes: Attach the documented procedure or procedures for the handling, storage, assignment, control, and non-return of keys, in the installations, offices, interiors, and critical and/or sensitive areas. Ensure that these procedures include the following points: a) Responsible for administering and controlling the security of keys. b) Control record for key lending. c) Indicate the treatment for loss or non-return of keys. d) State if there are areas where access is granted with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow for clear identification of personnel, materials, and/or equipment present, including the following areas: entrances and exits, handling areas, cargo loading, unloading and storage, perimeter and/or peripheral walls, interior fences and parking areas, and must have an emergency and/or backup system in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: a) Indicate which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant). b) How do you ensure that the lighting system is appropriate in each of the areas of the inspected premises, as well as that it has continuity in the event of power failure in each of the areas of the installation and with special emphasis on areas considered as critical and/or sensitive, so as to allow clear identification of personnel, materials and/or equipment it covers. c) Person responsible for the control and maintenance of lighting systems. d) Maintenance and inspection program (if it coincides with another process, indicate it). The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting. 2.7 Communication devices. The inspected premises must have communication devices and/or systems for the purpose of contacting security personnel and/or emergency and security authorities as required, in an immediate manner. Additionally, it must have a backup system and verify its proper functioning periodically. Response: Explanatory Notes: Describe the procedure that personnel must perform to contact the company's security personnel or, if applicable, the corresponding authority in the event of any security incident. Indicate whether operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert buttons and/or emergency) to communicate with security personnel and/or whoever is appropriate (these must be accessible to users, to be able to react promptly). Indicate what communication devices the company's security personnel uses (landline phones, cell phones, radios, alarm system, etc.).
Describe the procedure for the control and maintenance of communication devices, ensure you include the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate if you have backup communication devices, in case the permanent system fails and, if applicable, detail briefly. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Verification and maintenance records of the devices. c) Method of assignment of communication devices. 2.8 Alarm systems and closed-circuit television and video surveillance systems. Alarm systems and closed-circuit television and video surveillance systems and security technologies must be used to monitor, notify or deter unauthorized access and prohibited activities in the facilities and other areas considered sensitive, notify the corresponding area, in addition to being used as evidence in investigations derived from any incident. These security systems and technologies must be placed according to a prior risk analysis and applicable regulations, in such a way as to allow clear identification of areas involving the handling, storage, custody, loading and unloading of foreign trade merchandise, security inspections of cargo vehicles, as well as the entry and exit of authorized personnel, visitors, suppliers, passenger vehicles, and other areas considered sensitive on a permanent and uninterrupted basis in accordance with their operation and the coordination established with the customs office, the DGIA or the AGCTI, as applicable. The inspected premises must have documented operating procedures for the aforementioned systems. In the case of alarm and closed-circuit television and video surveillance systems, it must include supervision of the good condition of the equipment, verification of the correct position of the cameras, maintenance for the backup of recordings for at least sixty days in accordance with rule 2.3.8, continuity in operation in the event of power supply failures, as well as those responsible for their operation. These systems must have restricted access. Response: Explanatory Notes: Mention the documented procedure indicating the operation of the external central alarm system or sensors, and if applicable, describe the following points: a) Indicate if all doors and windows have alarm sensors or motion sensors. b) Procedure to follow in case an alarm is activated. c) Indicate the personnel or area responsible for maintenance, how failures are reported and the records they use. Describe the documented procedure for the operation of alarm and closed-circuit television and video surveillance systems and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensure you include the following points:
a) Indicate the number of security cameras of the alarm and closed-circuit television and video surveillance systems installed, and their location by area, (detail if it covers the entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as the place of storage of foreign trade merchandise) and where the inspection referred to in sub-standard 7.2) takes place. Attach a layout or map of the distribution of security cameras. b) Indicate the location of the closed-circuit television and video surveillance systems and security technologies, where the monitors are located, who reviews them, as well as the operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Periodic and random reviews of recordings must be carried out. Indicate how they review them (random, every week, special events, restricted areas, etc.), who is the designated personnel and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept, which must be at least 60 days. e) Alarm and closed-circuit television and video surveillance systems and security technologies must have an alternative energy source that allows them to continue functioning in the event of an unexpected loss of direct power. For the above, indicate if the alarm and closed-circuit television and video surveillance systems and security technologies are backed up by an electrical power plant, or some other mechanism to supply electrical energy, that guarantee their operation. These systems should have an alarm/notification function, which indicates a failure condition in the operation and/or recording, indicate if your systems have such a function. f) Indicate if in addition to the closed-circuit television and video surveillance system, you use any other type of technology to strengthen the security measures you already have.
g) Describe the procedure that has been implemented to regularly test and inspect the closed-circuit television and video surveillance system and security technologies and ensure their proper functioning. The results of the inspections and the operational tests must be documented, as well as the necessary corrective actions (these must be implemented as soon as possible). Additionally, that the documented results of these inspections are kept for a sufficient time for audit purposes. h) Indicate if the provider of the alarm and closed-circuit television and video surveillance systems has access to the security cameras, if they are in charge of monitoring them, how access is controlled and who is responsible for said monitoring. 3. Physical access controls. Physical access controls are mechanisms or procedures that prevent and prevent unauthorized entry to the facilities, maintain control of the entry of employees and visitors and protect the company's assets. Access controls must include the identification of all employees, visitors and suppliers at all entry points. Likewise, records must be kept and the documented mechanisms or procedures for entry to the facilities must be permanently evaluated, being the basis for beginning to integrate security as one of the primary functions within any company. The evaluation of what is provided in this sub-standard will be carried out in accordance with the applicable regulatory provisions for the inspected premises. 3.1 Security personnel. The inspected premises must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and merchandise during its transport and handling within the company, as well as for controlling the access of all people to the property. Security personnel must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons or any incident in the installation. Management must periodically verify compliance with procedures, policies and functions through internal audits with the objective of verifying their correct execution. Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel and ensure you include the following points: a) Indicate the number of security personnel working in the company. b) Indicate the positions and/or functions of the personnel and operating hours. c) In case of hiring an external service, provide the general data of the company (Tax ID, Legal Name, address), and specify number of employees employed, operational details, records, reports, etc. d) In case of having armed personnel, describe the procedure for the control and safeguarding of weapons.
3.2 Employee identification. There must be an employee identification system for access to the facilities. Employees should only have access to those areas they need to perform their functions. Management or security personnel of the inspected premises must adequately control the delivery and return of badges, ID cards and/or employee identification credentials. Procedures for the delivery, return and change of access devices (for example, keys, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: a) Identification mechanisms (badge and/or photo ID, access control, biometrics, proximity cards, etc.). b) Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and removed (if applicable). c) Indicate how personnel hired by a business partner, who works within the facilities (contractors, subcontractors, in-house services, personnel from cargo handling companies, etc.) are identified. d) Describe how the company delivers, changes and withdraws employee identification and access controls and ensure you include the responsible areas for authorizing and administering them. The procedure must also describe how the company delivers, changes and withdraws employee identification and access controls and ensure you include the areas responsible for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). 3.3 Visitor and supplier identification. To access the facilities, visitors and suppliers must present official photo identification for documentation upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by premises personnel during their stay in the facilities and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented. In the case of suppliers and users who work regularly in the premises, the company must have a physical validation system for identification badges as established by the customs office of its jurisdiction to grant entry and exit authorizations, if applicable.
Response: Explanatory Notes: Describe the procedure for visitor and supplier access control, ensure you include the following points: a) Indicate what records are kept (personal forms for each visit, logbooks). b) The visitor and supplier record must include the following:
3.5 Courier and package deliveries. Courier and package deliveries intended for premises personnel must be examined upon arrival and before being distributed to the corresponding area. Likewise, the company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to the responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages and ensure you include the following: a) Indicate the personnel in charge of carrying out the procedure. b) Indicate how the service provider is identified (indicate if it requires an additional procedure to the supplier access procedure). c) Indicate how the review of the courier and/or packages is carried out, what mechanism it uses, the records that are kept and, if applicable, the incidents detected. d) Describe the characteristics or elements to determine what courier and/or packages are suspicious. e) Indicate what action you take in the event of detecting suspicious courier and/or packages. 4. Business partners. The inspected premises must have written and verifiable procedures for the selection and contracting of new business partners and monitoring of partners with whom it is already working, such as: Transporters for the transport and/or distribution of merchandise subject to foreign trade, warehouses, providers of cleaning, private security, personnel hiring, placement and maintenance of alarm and closed-circuit television and video surveillance systems, providers of Information Systems and Technologies, providers of cargo loading, unloading and maneuvering services, contractors; shipping or airline lines, among others, and according to their risk analysis, require them to comply with security measures to strengthen the international supply chain. The risk analysis that the premises carries out regarding its business partners (clients and suppliers) must include risks related to the identification of activities related to money laundering and terrorist financing. Additionally, the premises must foster a documented social compliance policy and program that, at a minimum, addresses how among its employees and business partners they could guarantee that goods, inputs or merchandise imported into Mexico for the manufacture of products or merchandise do not come from extraction, production or total or partial manufacturing, with prohibited forms of labor, that is, forced or compulsory, including forced or compulsory child labor, under article 23.6 of the USMCA and the Agreement establishing the merchandise whose importation is subject to regulation by the Ministry of Labor and Social Welfare, published in the Official Gazette on February 17, 2023. 4.1 Selection criteria. There must be documented procedures for the selection, follow-up and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods and use of the information provided. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of business partners must include, indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews or evaluations of said partners for the identification and control of activities related to money laundering and terrorist financing. If the investigation and/or evaluation of any business partner leads to substantial doubts about the veracity of their operations or services, the premises must avoid their hiring and, if applicable, notify their security specialist or Authorized Economic Operator Program contact and the corresponding authority about their suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new business partners and monitoring of the partners with whom it is already working, this comprises any type of business associates, suppliers who have commercial relationship with the company and if applicable with its logistical process and with the supply chain, as well as with potential and predominant clients to hire their service frequently and/or those who have a commercial relationship with the inspected premises and ensure it includes the following points: a) What information is required from your business partner. b) What aspects are reviewed and investigated (the result of the investigation must be integrated into the file). c) Indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses. This point refers to pointing out all those alerts to determine that a business partner is not reliable and thus, carry out a deeper investigation and evaluate whether to work with them. d) Indicate if you maintain a file for each of your business partners, as well as the information it must contain. e) Indicate how you evaluate the services of your business partner and what points you review. The file must include at least the following: a) Company data (name, Tax ID, activity, etc.). b) Legal representative data. c) Proof of address. d) Commercial references (if applicable). e) Contracts, agreements and/or confidentiality agreements and security policies. f) If applicable, certificate or certification number in the security programs to which it belongs.
4.2 Security Requirements. The supervised facility must have a documented procedure in which, based on its risk analysis, it requests additional security requirements from those commercial partners involved in its supply chain, as well as from service providers that similarly intervene in the control, handling, transport, and/or coordination of merchandise subject to foreign trade, such as: transport, warehouses, service providers for cleaning, private security, personnel hiring, installation and maintenance of alarm and closed-circuit television and video surveillance systems, Information Technology system providers, providers of loading, unloading and handling services for merchandise, collection and recycling, contractors, among others. The requirements must be based on the Supervised Facility Profile established by the AGACE or the specific Profile for each actor in the supply chain that corresponds to them, if one exists. The supervised facility must request from its commercial partners documentation that certifies or proves that they comply with the minimum security standards established in the Supervised Facility Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses with documentation that supports compliance with the requirements established in the Authorized Economic Operator Program. Similarly, the facility must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of the facility's commercial partners that provide their services within the facilities, they must be obligated to comply with these supply chain security requirements. Response: Explanatory Notes: Describe the procedure that indicates how it carries out the identification of commercial partners that require compliance with minimum standards in terms of security. Ensure to include the following points: a) A register of the commercial partners that must comply with security requirements, and mention what type of providers these are (transporters, warehouses, private security companies, customs brokers, companies authorized to provide loading, unloading and merchandise handling services, etc.). b) Indicate in what documentary way (agreements, accords, contractual clauses and/or addenda) it ensures that its commercial partners comply with security requirements. c) Indicate if there are agreements, contractual accords, contractual clauses and/or addenda regarding the implementation of security measures with its service providers within its company, such as: customs brokers, security guards, cleaning services, gardening, cafeteria, maintenance, Information Technology providers, etc. d) Indicate if it has commercial partners to whom it is required to belong to a supply chain security program, either by certification by a foreign authority or the private sector (for example: C-TPAT or any other Authorized Economic Operator Program) as well as the information and documentation requested of them.
4.3 Commercial Partner Reviews. The supervised facility, through the Security Committee, must carry out periodic security evaluations (as well as those derived from risk situations) of the processes and installations of business associates based on risk to guarantee that they have the minimum security standards required by the facility, based on the Authorized Economic Operator Program, maintain records that allow verifying that the processes and security measures are being executed as well as the corresponding follow-up. When inconsistencies are found, the company must communicate this to its partner or supplier and provide a justified period to address the observations or areas for opportunity identified, or otherwise, have the necessary measures to sanction them. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program; therefore, in addition to a documented procedure, there must be a program or schedule for the execution of these security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners are functioning correctly, it puts its supply chain at risk. Response: Explanatory Notes: Describe the procedure to carry out security evaluations for the verification of security processes and installations of commercial partners; ensure to include the following points: a) Frequency with which visits to the commercial partner are made (this must be at least once a year and derived from risk situations). b) Program or schedule for the execution of security reviews. c) Record or report of the verification and, if applicable, the corresponding follow-up. d) The verification format(s) must be duly completed, placing the date, name and position of those participating in the review, signatures, etc. e) Indicate what action measures are taken in case commercial partners do not comply with the established security requirements. f) In case of having commercial partners with C-TPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed and the actions taken in case it is detected that it is suspended and/or cancelled, in accordance with what is established in its procedure. The procedure must include: a) Frequency of visits. b) Points of review in terms of security. c) Preparation of reports. d) Feedback and agreements with the commercial partner. e) Follow-up on agreements. f) Measures in case of detecting non-compliance with requirements. g) Record of evaluations. h) Area or person responsible for carrying out this procedure.
5.2 Warehouses and Distribution Centers. In case the supervised facility has commercial partners that provide some warehouse, distribution center or other services within its facilities, they must be subject, according to their characteristics, to what is established in this document, with the objective of maintaining integrity in its supply chain. Response: Explanatory Notes: According to its logistical process mapping, if foreign trade merchandise is transferred or moved to another warehouse and/or alternative distribution center different from the one operated under its authorization or concession as a supervised facility, it must indicate if they are registered under its Tax ID (R.F.C.), providing their general data (name and address) and briefly explaining what activity is carried out in that or those facilities (cross dock, temporary warehouse, etc.). Likewise, indicate if these belong to the company or is a service contracted through a third party and/or are part of a shareholder group. In this case, in accordance with the supplier selection criteria mentioned in the section regarding Commercial Partners of this document, indicate in what way it ensures that they meet the minimum requirements in terms of security. Facilities that have a concession or authorization of Supervised Facility must coincide with the number of Profiles presented, as well as indicate all addresses that are registered under the RFC. 5.3 Delivery and Receipt of Cargo. The supervised facility must guarantee the supervision of the identification of operators of its own or subcontracted transport means, who carry out the collection, delivery or receipt of foreign trade merchandise inside or outside its facilities, warehouses and/or distribution centers. Likewise, it must designate the responsible area to supervise the loading or unloading of the shipment, even in accordance with the instructions received from clients for its handling and transfer. On the other hand, it must supervise, inspect and verify through mechanisms, tools or non-intrusive technology that it has available, the integrity of the transport means and of the merchandise subject to foreign trade that enters or leaves the supervised facility, comparing the information described in the exchange lists received previously in accordance with the traffic or transport mode in question. Similarly, it must guarantee that the driver who transports foreign trade merchandise, during delivery or receipt, has the required documentary information before being subjected to the formalities of customs clearance and authorizing its exit. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to guarantee that these areas remain free of visible contamination by pests. During the process of loading and unloading merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise or pests) and register said review (incident reports, records, reports, etc.). Also, the personnel responsible for the entry and exit areas of the merchandise must review the information included in the import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on the identification of common errors in the documentation of export shipments, with the objective of preventing these from resulting in security incidents or suspicious merchandise.
Response: Explanatory Notes: Attach the documented procedure in which it indicates how it carries out the delivery and receipt of cargo and ensure that the following points are included: a) Method to identify transport operators. b) Documentation delivered to operators. c) Responsible for supervising the identification numbers of the transport means during the loading or unloading of containers, dry boxes, UDLS, railway platforms, air waybills, if applicable, in the case of consolidated merchandise, de-consolidation process and comparison of information. Inspection method at the facility access point. a) Designation of the personnel responsible for receiving the driver and the merchandise upon arrival. b) Coordination of the facility areas that receive the exchange lists from the transporters prior to their arrival and with the customs where the formalities of customs clearance are fulfilled. c) Record of the introduction to the supervised facility of consolidated merchandise. d) Release deadlines. e) Prior requests. f) Services offered by the facility for the movement of merchandise prior to its customs clearance. g) How it guarantees that the transport means is free of visible contamination by pests, in case any type of visible pest, contamination, trash, insects, grass, weeds or brush is identified, how it is reported and what actions are taken regarding it. Attach the documented procedure to detect and report discrepancies in the delivery or receipt of transport means that transport merchandise and ensure that it includes the following points: a) Responsible for carrying out the review. b) Documents to compare. c) Areas to which the information is reported.
5.4 Merchandise Tracking Procedure. In accordance with its risk analysis, the supervised facility must monitor the movement of foreign trade merchandise in its installation through a tracking and activity supervision diary or a technology during the arrival, storage, custody and release of foreign trade merchandise to comply with the formalities of customs clearance, guaranteeing at all times having the following information: number and information of the bill of lading, packing list, waybill or other transport documents, as applicable, name and address of the consignee or sender, description, value, origin of the merchandise and the physical location in the facility. The foregoing must be accredited in accordance with the guidelines of a documented procedure. The supervision data and registration of all maneuvers in the supervised facility must be preserved for one month in case the authority must carry out an evaluation when so required. Response Explanatory Notes: Attach the documented procedure to monitor the transfers, internal transfers in the supervised facility of consolidated and/or de-consolidated foreign trade merchandise. This procedure must include, among other aspects according to its operation: a) Indicate the type of system implemented in its case, the consultation tools it has available to monitor the merchandise. b) Identification of estimated times for transfer and maneuvers in supervised facilities according to the transport in question. c) Detail the communication means it has available. d) In case the tracking is carried out by a third party, indicate who is responsible, and how it is verified that it is being carried out correctly, in accordance with the procedures that the company indicates to it. 5.5 Cargo Discrepancy Report. There must be documented procedures to detect and report missing, surplus, prohibited merchandise or any other discrepancy in the delivery or receipt of containerized, consolidated and/or de-consolidated merchandise prior to complying with the formalities of customs clearance, with the purpose of having information that aids in the corresponding investigations by authorized consignees and, if applicable, by competent authorities. Likewise, it must describe the measures and actions to be taken in case of identifying the transfer and handling of illicit, undeclared and prohibited merchandise or those that by their nature put the safety of users at risk, which could be during the following processes: reception, delivery, warehouse for prior inspections, consolidated, de-consolidated, transport means yards and, if applicable, according to the services offered. Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of merchandise and ensure that it includes the following points: a) Responsible for carrying out the review. b) Documents to compare. c) Areas to which the information is reported. This procedure must be applied to consolidated merchandise and located in the warehouse. Describe and enumerate the risk areas identified in the supervised facility.
5.6 Processing of Cargo Information and Documentation. The supervised facility must have documented procedures to ensure that the electronic and/or documentary information used during the movement, storage, custody, maneuvers and dispatch of the cargo, as well as the information received from business associates, is legible, complete, accurate, reported in real time and protected against changes, losses or introduction of erroneous information. Similarly, the forms and documentation related to import and/or export should be secured to avoid unauthorized use. Response: Explanatory Notes: Describe the procedure for the processing of cargo documentation; ensure to include the following points: a) Detail how it transmits and/or receives information related to the transfer and maneuvers of cargo in the supervised facility (indicate if it uses a specific computer control system and briefly explain its function). Likewise, detail how it validates that the information provided by foreign trade users, transporters, shipping lines, railway companies, among others that converge in the facility, is legible, complete, accurate, reported in real time and protected against changes, losses or introduction of erroneous information. b) The electronic information of the shipments and cargo in general must include the seal and/or lock number with which the cargo was secured. c) Indicate in what way business associates transmit information with the supervised facility and ensure its protection. 5.7 Inventory Management, Control of Packaging, Container and Packing Material. The supervised facility must have documented procedures for automated inventory control, in accordance with its authorization to provide services for handling, storage and custody of foreign trade merchandise; likewise, they must include abandonments, destructions, among others in accordance with applicable regulations and conduct reviews periodically. Packaging, container, and packing materials, if applicable, must be controlled and supervised to prevent them from being susceptible to manipulation prior to their use, which also includes, the control, dissemination and prevention procedure of visible contamination by pests, in the case of using wooden packing materials (such as pallets, boxes, crates, cages, reels, lashing, chocks, supports or platforms) to stack the cargo, move it and protect it throughout its entire supply chain. Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, according to its operation among other aspects, the following: a) Mention what type of system it uses for the exchange of information with the authority for inventory purposes. b) Who is its provider. c) Indicate if it has a contingency plan in case of system failures.
d) Mention where it is physically located and who are the responsible parties for its operation. e) The frequency with which it carries out inventory verification (periodic inventory). Indicate if there is a documented scheduled calendar to carry them out. f) Indicate what is done in the case of surpluses and shortages in inventories. g) Specify the treatment provided for the control and handling of packaging, container, and shipping material, and if applicable, shrinkage, waste, or leftover material, which also includes the control, dissemination, and prevention procedure for visible pest contamination, in the case of using wooden shipping materials (such as pallets, boxes, crates, spools, dunnage, supports, or platforms) to stack, move, and protect the cargo. h) This point is also focused on reducing the risk of introduction or dissemination of quarantine pests of importance to the country through packaging (imports); therefore, describe how you comply with the provisions established by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144-SEMARNAT-2017, in accordance with International Standards for Phytosanitary Measures No. 15, titled "Regulation of Wood Packaging Material in International Trade," which emanate from the Food and Agriculture Organization of the United Nations. i) Specify how the fumigation process is carried out to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions do you take if quarantine of the packaging materials is required? j) Indicate the area responsible for carrying out this process, as well as the documentation or certificates obtained.
The applicant's procedures may include: a) Warehouse accessible only to authorized personnel. b) Control of incoming goods, transfers to other warehouses, consolidation or de-consolidation. c) Actions taken if irregularities, discrepancies, losses, or thefts are identified. d) Treatment of deterioration or destruction of goods. e) Separation of various types of goods, for example: high value, hazardous.
6.1 Customs Obligations. The supervised facility must have a documented procedure for compliance with customs obligations due to holding a federal authorization. This must include at least the following: a) the annual guarantee that must be paid to the tax authority based on the average value of the goods handled; b) The identification of the physical space for customs inspections carried out by customs authorities; c) the physical space designated for handling, storage, and custody services regarding goods that have become property of the federal treasury; d) the free storage and custody of goods in accordance with regulations; e) process for transferring goods between warehouses; f) process to prove payment of fees for being a supervised facility; g) regarding the authorization for goods to be subject to manufacturing, transformation, or repair, if applicable.
Furthermore, the procedure mentioned in the previous paragraph must include the communication process with consignees in the event of destruction or loss of goods, guarantee the exchange of information through a simultaneous system containing the data indicated in rule 2.3.8., and establish protocols related to the treatment, communication, storage, and custody of foreign trade goods under the internal transit regime.
Response: Explanatory Notes: Attach the procedure to comply with your customs obligations, which must include the following: a) The annual guarantee that must be paid to the tax authority based on the average value of the goods handled. b) The identification of the physical space for customs inspections carried out by customs authorities. c) The physical space designated for handling, storage, and custody services regarding goods that have become property of the federal treasury. d) The free storage and custody of goods in accordance with regulations. e) Process for transferring goods between warehouses. f) Process to prove payment of fees for being a supervised facility. g) The communication process with consignees in the event of destruction or loss of goods.
6.2 Customs Verification. The supervised facility, in order to guarantee the compliance of operation information for the customs clearance of foreign trade goods, as well as to verify the truthfulness of the information declared to competent authorities, must have documented procedures to verify that the customs declarations it receives for release from the facility match what is registered in SAAI Web, and if applicable, report any discrepancy in said information to the customs authority. The facility must also have a procedure for archiving the corresponding release records and safeguarding them for at least one month.
Response: Explanatory Notes: Attach the established procedure to verify the information registered in SAAI Web, and cross-check that contributions and/or compensatory quotas had been paid prior to the release of shipments to undergo the formalities of customs clearance. Specify how business partners transmit information to the supervised facility and ensure its accuracy, for example: the use of the institutional application "Remote Declaration Inquiry" to corroborate the payment of contributions and/or compensatory quotas, identification of means of transport, weight, among others, for exit authorization.
In the event of using high-security seals, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the moment they leave the facility. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must comply with or exceed ISO Standard 17712 for high-security seals.
With the objective of maintaining supply chain security, the facility must systematically inspect all cargo vehicles upon entry and exit from its facilities (domestic and international traffic), in addition to keeping a record.
7.1 Use of Seals and/or Padlocks. The supervised facility, if applicable, must identify the cargo transport means, own or subcontracted, that transport complete or consolidated foreign trade goods, which may be: maritime, air, national land, cross-border, railway, and/or multimodal, that are subject to the placement of seals and/or padlocks that comply with or exceed ISO Standard 17712, with the aim of guaranteeing the integrity of the cargo at all times.
Therefore, as one of the security mechanisms, the supervised facility, if applicable, must use high-security padlocks or seals that comply with or exceed ISO Standard 17712 on all containers and loaded trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. To this end, the facility must have documented procedures to place and verify the correct application of seals, inspect them at intermediate points, final destination, and replace them when opened by any authority. In the event of such an inspection, drivers must notify and register any unusual anomaly or structural modification found in the means of transport resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols to commercial partners involved in the supply chain, and the investigation of the security incident. These must be notified to security personnel, commercial partners that may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program.
Likewise, it is necessary to have a documented procedure for the administration thereof, which includes the control, assignment, safeguarding, handling of discrepancies, and destruction of seals and padlocks (the latter is mandatory whenever seals are broken within the facility). Regarding the provider of seals and/or padlocks, it must be demonstrated how these comply with ISO Standard 17712. The company management or a security supervisor must carry out periodic and documented audits of high-security seals and/or padlocks; these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-check with inventory records and shipping documents. Also, supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in means of transport and International Traffic Instruments to corroborate that the information is correct.
In this case, the supervised facility must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or padlocks on means of transport carrying foreign trade goods in accordance with its logistics process and in those traffics that require it due to their high probability of occurrence and impact of the identified risk and during maneuvers in the facility. It must evidence controls that allow accrediting that it supervises the portability of seals and/or padlocks resulting from entries or exits of the supervised facility. In all cases, it must use the VVTT inspection method to mitigate improper manipulations as follows: a) V - View the seal and lock mechanisms of the container. b) V - Verify the seal number. c) T - Pull the seal to ensure it is correctly placed. d) T - Twist and turn the seal to ensure.
Response: Explanatory Notes: List, according to your risk analysis and logistics process, the means of transport that are subject to the placement of high-security seals and/or padlocks. Attach the documented procedure for the supervision of placement and review of seals and/or padlocks on means of transport carrying foreign trade goods. This must include, among other aspects according to your operation: a) The use of seals and/or padlocks that comply with or exceed ISO Standard 17712. b) If applicable, use the VVTT inspection method.
If applicable, attach the documented procedure for the control and handling of seals and/or padlocks; this must include, among other aspects according to your operation: a) What type of seals and/or padlocks you use in your operations (foreign trade, transit, storage, etc.). b) Who has access and how padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (record of seals used, as well as receipt of new seals and/or padlocks). c) Describe how the facility management or security supervisor participates in audits of high-security seals and/or padlocks, the reviews they perform, the records they generate, and the actions they take in case discrepancies are identified. Also, how supervisors of the shipping area and/or warehouse managers verify seal numbers used in means of transport and International Traffic Instruments to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). d) How discrepancies in seal and/or padlock numbers are addressed. e) Indicate who the supplier(s) are and how it is proven that the specifications of seals and/or padlocks comply with ISO Standard 17712 (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO).
All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of means of transport, containers, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of means of transport, containers, train cars, trailers, and/or semi-trailers used as International Traffic Instruments, entering or leaving the supervised facility according to their nature, including the reliability of the locking mechanisms therein, with the aim of identifying natural or hidden compartments.
Inspections of means of transport or cargo vehicles, containers, and trailers must be systematic and carried out upon entry and exit from the supervised facility and, if applicable, at the cargo loading point; a record of these inspections must be kept in an area with controlled access and carried out in a place monitored by alarm systems and closed-circuit television and video surveillance; said system must cover the inspection process in its entirety.
The documented procedure for its inspection must include, by way of example and not limitation, the following review points for road transport:
| Means of Transport | Trailers, Train Cars, Semi-trailers, and Containers |
|---|
For means of transport with a trailer or integrated cargo compartment, the items indicated in the Trailers section must be added to the means of transport points.
Similarly, before loading means of transport, containers, train cars, trailers, and semi-trailers used as International Traffic Instruments, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide contraband or have been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of foreign trade goods, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination.
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of means of transport according to their nature and logistics process involved in the entries and exits of the supervised facility. This must include, among other aspects according to your operation: a) Those responsible for carrying out the inspection. b) Definition of the location(s) where the inspection takes place and indicate how it is monitored by alarm systems and closed-circuit television and video surveillance. c) The security review points for means of transport, trailers, semi-trailers, containers, railway transport, and/or multimodal according to official provisions, both of security and those of quality and agricultural inspections, with the aim of looking for visible pests. d) Established formats for the inspection of means of transport. e) Attach the established format for the inspection of means of transport or cargo vehicles, containers, train cars, trailers, and/or semi-trailers. If you use other types of cargo vehicles for the transport of your goods (vans, pickups, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points.
Furthermore, the security and agricultural inspection format must include the following information: a) Date of inspection; b) Time of inspection; c) Vehicle license plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected; and, f) Name of the employee performing the inspection and the supervisor.
The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation. The documentation must be preserved for one year for investigation in the event of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
Additionally, and based on the risk analysis, the supervised facility should carry out periodic random reviews of cargo vehicles, after the transport personnel has performed security inspections, to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents. The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the means of transport may be susceptible to contamination.
7.3 Storage of vehicles, means of transport, containers, train cars, trailers, and semi-trailers. In the event that the means of transport, containers, trailers, and/or semi-trailers intended to transport foreign trade goods are empty and must be stored in parking areas, they must be secured with a lock and/or indicative seal, or, in their case, in a secure area that is guarded and/or monitored. When it is necessary to store any loaded container, trailer, and/or semi-trailer, it must be located in a secure area monitored by alarm systems and closed-circuit television and video surveillance systems, to prevent unauthorized access and manipulation of the goods; therefore, it must be closed with a high-security seal and/or lock in accordance with ISO 17712 Standard. Response: Explanatory Notes: Indicate whether the company stores containers, trailers, and/or semi-trailers for subsequent dispatch, or in the case of those that are empty, and how it maintains their integrity within its facilities. a) In the event of using locks and/or seals, indicate what type is used. b) In the event of using any containers, trailers, and/or semi-trailers as storage for raw materials and/or any other type of goods, indicate how it maintains their integrity and security. 8. Personnel Security. The supervised facility must have documented procedures for the registration and evaluation of persons wishing to obtain employment within the supervised facility, establishing methods to conduct periodic verifications of current employees. Furthermore, there must be continuous training programs for administrative and operational staff in which the company's supply chain security policies, consequences, and actions to be considered in the event of any violation are disseminated. 8.1 Verification of work history. The supervised facility must have documented procedures to investigate and verify the information recorded in the curriculum vitae, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either on its own or through an external company. Likewise, for positions that require it due to their sensitivity and affect the security of shipments, in accordance with the risk analysis previously conducted, stricter requirements for hiring must be considered, which must be carried out periodically. Regarding personnel already working in the company, periodic investigations must be conducted based on the activities and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for hiring personnel, and ensure you include the following: a) Requirements and documentation demanded. b) Tests and exams requested. Indicate the areas and/or critical positions identified as risky, according to your analysis, and indicate the following: a) Indicate if there are additional requirements for specific areas and/or work positions, such as criminal records (if legislation and company policies allow), certificate of non-criminal record, socioeconomic studies, clinical toxicological studies (drug use), etcetera. In their case, indicate the positions or work areas where they are required and with what frequency they are carried out. b) Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. In the event of hiring a service agency for personnel hiring, indicate if it has documented procedures for personnel hiring and how it ensures compliance with the same. Briefly explain what they consist of. The procedures for personnel hiring and contractors must include: a) Exhaustive investigations of the work and personal backgrounds of new employees. b) Confidentiality and liability clauses in employee contracts. c) Specific requirements for critical positions. d) In their case, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. The facility may consider the results of candidate background verifications, as permitted by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Procedure for personnel dismissal. There must be documented procedures for personnel dismissal, which include the delivery of identification, and any other item provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etcetera). Likewise, this procedure must include the deactivation in computer and access systems, among others that may exist. Response: Explanatory Notes: Describe the procedure for personnel dismissal, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the delivery of identification, uniforms, keys, and other equipment is carried out and confirmed. c) Indicate the control, record, and/or format, in which the delivery of material and deactivation in computer systems (in their case, attach) is identified and ensured. d) Indicate the type of records of personnel who ended their employment relationship with the company, so that in case it was for security reasons, their service providers and/or business associates are warned. 8.3 Personnel administration. The supervised facility must maintain an updated system, control, or database of active employees. Likewise, it must carry out and maintain updated records of affiliation to social security institutions and other legal labor records. In the event that the company has personnel hired by its business partners and works within the facilities, it must ensure that they comply with the requirements established for the rest of its employees. Response: Explanatory Notes: Indicate that the facility has an updated system, control, or database, both for personnel hired directly and that hired through a service provider company, and ensure it includes, among others, the following points: a) Full name. b) Updated photograph at least every 5 years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etcetera). d) Affiliation. e) Work history. f) Diseases. g) Medical exams. h) Training. i) Psychometric exams. j) Toxicological exams. k) Results of periodic evaluations. l) Observations. This personnel must be hired in accordance with current labor laws and regulations.
Response: Explanatory Notes: Attach the procedure for the recovery (or replacement) of Information Technology systems and/or data, which includes how it backs up and ensures the security of its information as well as protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which backups are carried out. b) Who has access to them, and who authorizes the recovery of information. c) Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. d) Mention if, to carry out this type of tests or vulnerability scans, it does so through software, a third party or provider, and, in their case, indicate the name or corporate name. e) In the event of finding vulnerabilities, describe the corrective actions that must be implemented. f) Indicate if it shares information about cybersecurity threats with its business partners participating in its supply chain (for example: communications, bulletins, emails, etcetera). g) Systems must be protected under passwords and must be modified frequently; therefore, indicate the procedure for changing them. h) Indicate if there are information security policies for their protection. i) Have a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to its systems and/or Information Technology data, as well as the abuse of the policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in the event of the detection of any violation of Information Technology systems and security policies.
Information Technology and cybersecurity policies and procedures must be reviewed annually and updated as a result of an attack or according to situations that may put the company's systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In the event of allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to securely access the company network. Indicate if business partners have access to the company's computer systems. In their case, indicate what programs and how they ensure control of access to them. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the supervised facility's information must also include at least the following: a) How and for how long data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in case of incident and how to recover information. c) Frequency and location of backups and archived information. d) If backups are stored in sites alternative to the facilities where the Data Processing Center is located. e) Tests of the validity of data recovery from backups. The procedures regarding the protection of the supervised facility's information must also include: a) An updated and documented policy for the protection of computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encripted format. b) Detail if it operates with multiple systems (sites/locations) and how such systems are controlled.
c) Who is responsible for the protection of the computer system (responsibility should not be limited to one person but to several so that each can control the actions of the rest). d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information should be limited to personnel authorized to modify and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, in their case, report that access to confidential systems is based on job requirements. e) Indicate the elements or formats that passwords must have, for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or what area provides those passwords. f) Indicate the name of the "firewall" and anti-virus used (include licensing related), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses. All computer equipment, electronic media (hard drives, cell phones, etcetera), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be disposed of, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage. g) In the event of personnel dismissal, access to computer equipment, telecommunications, and network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etcetera. h) Measures planned to handle incidents in case the system is compromised.
10.1 Training and awareness on threats. The supervised facility must have a training and awareness program on security policies in the supply chain directed to all its employees, and additionally, make available informational material regarding the established procedures in the company to consider a situation that threatens its security and how to report it. Training records must include the date of the training, the names of the attendees, and the topics of the training. Similarly, specific training must be offered according to their functions to help employees maintain the integrity of the cargo, perform inspections of containers, trailers, and/or semi-trailers for agricultural and security purposes, receive and review mail and packages, prevent operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and report internal conspiracies, protect access controls, as well as training regarding smuggling, theft of goods, placement of high-security seals and locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee onboarding and maintain periodic update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the procedures of the supervised facility. In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies and procedures, including access to computer equipment and systems via passwords or phrases; personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and maintain periodic update programs. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives.
Response: Explanatory Notes: It must have a training program on security and prevention in the supply chain for all direct and indirect employees. Briefly explain what it consists of and ensure you include the following: a) Brief description of the topics taught in the program. b) When they are taught (Onboarding, specific periods, etc.). c) Frequency of training and, if applicable, updates. d) Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all the objectives of the same. e) Explain how employee participation in security matters is encouraged. Training to perform inspections of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments. b) Smuggling hidden in natural compartments. c) Signs of pest contamination. d) Procedures to follow if something is found during an inspection of the means of transport or if a security incident occurs during transit. e) Agricultural review training must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with International Phytosanitary Measure Standard No. 15, named Regulation of wooden packaging used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations, and the identification of infested wood.
10.2 Awareness for transport operators. The supervised facility must make known to the operators of the means of transport used for the transfer of goods destined for foreign trade, the security policies regarding agricultural and security inspection procedures of means of transport, loading and unloading, incident management, change of locks in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of means of transport must be trained to inspect cargo vehicles for such purposes. In the case where the transport service is provided by a business partner, it must ensure that operators know all established security policies and procedures.
Response: Explanatory Notes: Describe the dissemination program on security in the supply chain focused on transport operators and ensure you include the following: a) Indicate how this dissemination is carried out. b) Point out the topics covered. c) In case of using the services of a business partner for the transfer of your goods, indicate how operators are informed of the company's security policies and procedures. d) Indicate how participation in supply chain security training of transport operators is documented (videos, attendance lists, brochures, etc.).
The topics that must be included, by way of example and not limitation, are: a) Access and security policies at the facilities. b) Delivery-receipt of goods, (including suspicious cargo shipments). c) Confidentiality of cargo information. d) Transfer instructions. e) Accident and emergency reports. f) Instructions for the placement of high-security locks and/or seals in case of inspection by other authorities, as well as the control and use of high-security seals and locks in transit (placement of a new one, review after any authorized stop, etc.). g) Installation and testing of security alarms and unit tracking, when applicable. h) Identification of authorized formats and documents to be used. i) Signs of hidden compartments. j) Smuggling hidden in natural compartments. k) Signs of pest contamination. l) Procedures to follow if something is found during an inspection of the means of transport or if a security incident occurs during transit.
11.1 Reporting of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities related to the security of the supply chain and in accordance with its logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be notified to security personnel, business partners who may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of such anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to report or report anomalies and/or suspicious activities, as well as the mechanisms to anonymously report problems related to security, ensure you include the following: a) Who is responsible for reporting incidents. b) Detail how it determines and identifies with which authority to communicate in different scenarios or presumption of suspicious activities. c) Mention if it keeps a record of reporting anomalies and/or suspicious activities and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to report or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent recurrence, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that require it. This information must include the documentation generated to carry out the foreign trade operation of the affected goods that allows identifying each of the processes the goods went through until the point where the incident was detected and that allows recognizing the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any security incident, and ensure you include the following: a) Responsible for carrying out the investigation. b) Documentation that integrates the security incident file. The documents in the file derived from the investigation must include at least the following: a) General information of the shipment, service order. b) Transport request; confirmation of means of transport; identification of the transport operator (access records, exit records, security inspection records, etc.). c) Means of transport inspection formats; exit orders; records of collection, delivery, and receipt of foreign trade goods. d) Videos from alarm systems, closed-circuit television, and video surveillance. e) Documentation generated by and for business partners, and customs authorities. f) Unit tracking and monitoring report (GPS tracking).
E8. Profile of the Strategic Supervised Premises. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data provided will replace the data provided when you requested your authorization. General Information The objective of this Profile is to ensure that strategic supervised premises have security practices and processes implemented at their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products. Those interested in obtaining registration in the Certified Companies registry under the Strategic Supervised Premises modality referred to in rule 7.1.4., must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards, the application of a risk analysis culture supported by decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the company itself. What is established in this Profile must be accredited independently of the requirements and guidelines established for the control, surveillance, access routes, infrastructure, equipment, and security of foreign trade goods established by ANAM to grant the Strategic Supervised Premises authorization, and its compliance can be proven with that which coincides with what is established in this Profile. Filling Instructions:
You must fill out a Strategic Supervised Premises Profile for each of the facilities that have authorization as a strategic supervised premise. The number of Profiles presented must coincide with the facilities that have authorization for the limited-time introduction of foreign, national, or naturalized goods to strategic supervised premises, to be subject to handling, storage, custody, exhibition, sale, distribution, manufacturing, transformation, or repair in accordance with articles 14, 14-D, and 135-A of the Law manifested in your application for registration as a certified company under the strategic supervised premise modality as well as indicate all domiciles registered with the RFC.
Detail how you comply with or exceed what is established in each of the sections as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Description of the standard 1.1 Sub-standard. Description of the sub-standard Response. Explanatory Notes: Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards, therefore you must attach the procedures in Spanish that, if applicable, are required, or provide a detailed explanation of what is requested in the Response field. The section regarding Explanatory Notes is intended to be used as a guide regarding the points that must be included in the Response or in the attached procedures, as appropriate, of each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once the Strategic Supervised Premises Profile is answered, you must attach it to the Application for Registration in the Company Certification Scheme referred to in the first paragraph of rule 7.1.4., fraction IV. For the purpose of verifying what is stated in the previous paragraph, the SAT through the AGACE may carry out an inspection of the installation indicated here, with the exclusive purpose of verifying what is stated in this document.
Any incomplete Strategic Supervised Premises Profile will not be processed.
Any question related to the Application for Registration in the Company Certification Scheme and the Strategic Supervised Premises Profile, direct it to the contacts that appear on the SAT Portal.
In the case of being authorized with the Registration in the Company Certification Scheme, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and as a result changes or modifications are required in the information provided and given in this Strategic Supervised Premises Profile to the authority in accordance with what is established in rule 7.2.1., third paragraph, fractions III and IV.
When as a result of the inspection visit there are non-compliances related to minimum security standards, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the non-compliances indicated. Installation Data A Strategic Supervised Premises Profile must be filled out for each of the facilities that operate under the Strategic Supervised Premises authorization and that carry out handling, storage, custody, exhibition, sale, distribution, manufacturing, transformation, or repair processes of foreign trade goods. Installation Information Number of Strategic Supervised Premises Profile: of RFC Name and/or Business Name: Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of the installation (years of operation): Activity carried out in the installation: Preponderant products handled in the Strategic Supervised Premises: (As applicable) Avg. number of monthly shipments (EXP): Avg. number of monthly shipments (IMP): Total number of employees at this installation: Installation surface (m2):
Certifications in security programs: (Indicate if this facility holds a certification from any of the following programs) CTPAT. Yes No Level: Pre-Applicant: Applicant: Certified: Certified/ Validated: CTPAT Account number (8 digits): Date of last visit to this facility: Authorized Economic Operator from other countries (AEO) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration: Certifications: (Indicate if you hold certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The Strategic Supervised Premises must establish measures to identify, analyze, and mitigate security risks that could result in alterations to foreign trade merchandise during its handling, storage, custody, and transport in its supply chain and facilities, under the guideline of a documented procedure. This analysis must be based on the organization's model (e.g., type of merchandise, volume, clients, routes, information leakage, potential threats, etc.), so as to allow the implementation and maintenance of security measures. Based on the above, the Strategic Supervised Premises must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be updated at least once a year, so as to allow the permanent identification of other risks or threats considered in its operation and in the supply chain, as a result of some security incident or when changes occur in the initial conditions of the facility, as well as to identify whether the policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the facility's Security Committee must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate what are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the facility's installations, which must include at least the following points: a) Frequency with which it reviews and/or updates the risk analysis. b) Aspects and/or areas of the facility that are incorporated into the risk analysis. c) Methodology or techniques used to perform the risk analysis. d) Persons responsible for reviewing and/or updating the risk analysis of the facility. Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the risk assessment and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Identification of risks in its supply chain and its facilities. c) Risk analysis (causes, consequences, probabilities and existing controls to determine the level of risk as high, medium and low). d) Risk evaluation (decision making to determine the risks to be treated and priority for implementing the treatment). e) Risk treatment (application of alternatives to change the probability that risks occur). It is suggested to use risk management, governance and evaluation techniques in accordance with international standards ISO 31000, ISO 31010 and ISO 28000 that, according to your business model, should be implemented.
1.2 Security Policies. Strategic Supervised Premises must have a policy oriented towards preventing, securing, and recognizing threats to the security of the supply chain and company installations, such as drug trafficking, money laundering, arms trafficking, human trafficking, prohibited merchandise, and acts of terrorism. To promote a security culture, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. Senior officials or executives of the company who must endorse and sign the security policy can be the facility president, chief executive officer, general manager, or personnel with equivalent rank with decision-making authority.
Response: Explanatory Notes: State the security policy oriented towards preventing, securing and recognizing threats in the supply chain and company installations, indicate who is responsible for its review, signature and dissemination to employees, as well as the frequency with which its update is carried out. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the facility the company (reception, shipments, receipts, warehouse, etc.), and as part of the initial and reinforcement training of the company.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out periodic audits that allow evaluating all processes regarding security in the supply chain in a more critical and deep manner, as well as guaranteeing that its employees follow the facility's security procedures. Audits must be carried out by the company's Security Committee establishing a documented procedure, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, level of risk, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the facility's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. The senior management of the organization must review the results of the audits, analyze the causes, and undertake corrective or preventive actions required. The audit process must guarantee that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to which the facility's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain, ensure you include the following points: a) Indicate how the company carries out the scheduling or calendarization to perform an audit on security in the supply chain. b) Indicate who participates in them, and the records that are effectuated from them, as well as the frequency with which they are carried out. c) Indicate how the senior management of the facility verifies the result of the audits on security matters, how it performs and/or implements preventive actions, corrective and improvement actions in addition to the follow-up and closure of the same. d) The formats used during internal audits must be duly filled out, and through them, evidence that the procedures and security measures are being put into practice.
1.4 Contingency and/or Emergency Plans related to Supply Chain Security. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity in the event of a situation that affects the normal development of activities and foreign trade operations of the facility in its supply chain (in the facilities and during the transport, handling, storage, and custody of foreign trade merchandise according to its logistics process). A crisis or contingency may include the interruption of the transmission and exchange of commercial data due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a customs closure, a bomb threat, the detection of suspicious packages, a power outage, theft and/or damage to merchandise, threats or extortion, blockades or road closures, among others). Such plans must be communicated to personnel through periodic training, as well as carrying out tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness, from which a duly filled out and signed record must be maintained (for example: result reports, minutes or reports, which must be backed up by video recordings, photographs, etc., that demonstrate their execution).
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in case of an emergency or security situation, that affects the normal development of the facility's foreign trade activities in its supply chain (in the facilities, during the transport, handling, storage, and custody of merchandise, of foreign trade according to its logistics process).
This procedure must include, by way of illustration and not limitation, the following: a) What situations it contemplates, describing the plan of action and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. b) What mechanisms it uses to disseminate and ensure that these plans are effective. c) Contemplate the scheduling and carrying out of tests, practical exercises and annual drills and how they are documented (for example: result reports, minutes or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures and in the event that an irregularity has been detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, the territorial limits, as well as the various accesses, internal routes, and the location of the buildings must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others), and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damages to the facilities. Attach a general distribution or architectural plan, where the limits of the installations, access routes, emergency exits, location of the buildings, critical areas, parking lots, and boundaries can be identified.
2.2 Accesses in Doors and Booths. The entrance or exit doors for personnel and/or vehicles must be attended, controlled, monitored, and/or supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the installations, as well as the operating hours of each one, and indicate how they are monitored (in case of having assigned personnel, indicate the quantity). Detail if there are doors and/or accesses blocked, or permanently closed. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the perimeters of the Strategic Supervised Premises facilities, based on a risk analysis. Fences, interior barriers, or a mechanism must be used to identify and segregate in a particular manner, the areas for storage, custody, and warehousing of foreign trade merchandise, high value, dangerous, areas with restricted access, and others that it determines according to its risk analysis. These must be inspected regularly and keep a record of the review with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks. The storage, high value, dangerous, and/or restricted access areas must be clearly identified and monitored to prevent unauthorized entry.
Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls with which the installation is equipped, ensure you include the following points: a) Specify which areas are segregated. b) Point out their characteristics (material, dimensions, etc.). c) In case of not having walls, justify detailedly the reason. d) Frequency with which the integrity of the perimeter walls is verified, and the records that are kept, with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible. e) Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages. Describe how the cargo destined for foreign countries, dangerous material, and high value cargo is segregated; ensure you include the following points: a) Indicate how it separates national merchandise and foreign trade merchandise, and if it is additionally identified (for example: different packaging, labels, packaging, among others). b) Identify and point out the restricted access areas (dangerous merchandise, high value, confidential, etc.).
The procedure for the inspection of perimeter fences could include: a) Personnel responsible for carrying out the process. b) How and with what frequency the inspections of fences, perimeter walls, and/or peripheral and buildings are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that the repairs and/or modifications comply with the technical specifications and necessary security requirements.
2.4 Parking Lots. Access to the facility's parking lots must be controlled and monitored by security personnel or designated for this task. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas.
Response: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots, ensure you include the following points: a) Persons responsible for controlling and monitoring access to the parking lots. b) Identification of the parking lots (specify if the visitor and employee parking is separated from the storage and handling areas of merchandise). c) How entry and exit control of vehicles is carried out to the facilities. Indicate the records that are made for parking control, the existing control mechanisms (for example: ticket stubs, card readers, badges, etc.), how they are assigned and the area responsible for doing so. d) Policies or mechanisms to not allow the entry of private vehicles to the storage and handling areas of merchandise.
2.5 Key and Lock Device Control. Windows, doors, as well as interior and exterior fences, according to your risk analysis, must be secured with locking devices. The facility must have a documented procedure for the handling and control of keys and/or locking devices for the interior areas that have been considered critical. Likewise, a record must be kept and responsibility letters signed by persons who have keys or authorized access according to their level of responsibility and tasks within their area of work.
Response: Explanatory Notes: Indicate if all doors, windows, interior and exterior entrances have closing or security mechanisms. Attach the documented procedure for the handling and control of keys and/or locking devices, ensure they include the following points: a) Persons responsible for administering and controlling the security of keys. b) Format and/or control record for the loan of keys. c) Treatment of loss or non-return of keys. d) Point out if there are areas in which access is gained with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of persons, material, and/or equipment located there, including the following areas: entrances and exits, merchandise handling and storage areas, perimeter and/or peripheral fences, interior fences, and parking areas, and must have an emergency and/or backup system in sensitive areas.
Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: a) Point out which areas are illuminated and which have a backup system (indicate if it has an auxiliary power plant or any other mechanism to supply electricity in case of any contingency). b) How it ensures that the lighting system is appropriate in each of the areas of the facility so as to allow clear identification of personnel, material, and/or equipment located there. c) Person responsible for the control and maintenance of the lighting systems. d) Maintenance and review program (in case of coinciding with another process, indicate it). The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting.
2.7 Communication devices. The strategic supervised premise must have communication devices and/or systems with the aim of contacting security personnel and/or authorities immediately, in the event of an emergency or security situation. Additionally, it must have a backup system and verify its proper functioning periodically.
Response: Explanatory Notes: Describe the procedure that personnel must follow to contact the premise's security personnel or, in their case, the corresponding authority in the event of any security incident. Indicate whether operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or the relevant party (these must be accessible to users, to ensure a prompt response). Indicate what communication devices security personnel in the company use (landline phones, cell phones, radios, alarm systems, etc.). Describe the procedure for the control and maintenance of communication devices; ensure you include the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate whether you have backup communication devices in case the permanent system fails, and, if applicable, briefly describe them. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Record of verification and maintenance of devices. c) Method of assignment of communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance systems. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies, must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other considered sensitive areas, and to notify the corresponding area; they must also be used as evidence in investigations arising from any incident. These security systems and technologies must be installed according to a prior risk analysis, so that areas involving the access of personnel, visitors, suppliers, loading, unloading, storage, custody, and warehousing areas for foreign trade merchandise, security inspections of cargo vehicles, and other considered sensitive areas, remain monitored and watched. Such systems must allow clear identification of the area or environment being monitored and must be permanently recording and maintain a backup of recordings for at least sixty days, in accordance with what ANAM establishes for these purposes, in relation to Rule 4.8.17., and with the aim of having the necessary elements to assign corresponding responsibilities in the event of a security incident. Alarm systems, closed-circuit television, and video surveillance systems, and security technologies must have a documented operational procedure that includes supervision of the equipment's good condition, verification of the correct position of cameras, indication of the frequency with which recordings must be backed up, as well as those responsible for their operation. This system and all security technology infrastructure must have restricted access.
Response: Explanatory Notes: Mention the documented procedure indicating the functioning of the external central alarm system or sensors and, if applicable, describe the following points: a) Indicate whether doors and windows have alarm sensors, as well as the areas where motion sensors are available. b) Procedure to follow in case an alarm is activated. c) Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, and video surveillance systems, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances); ensure you include the following points: a) Indicate the number of security cameras installed in the alarm, closed-circuit television, and video surveillance systems, and their location by area (detail if it covers entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as the location of foreign trade merchandise storage). Attach a layout or map of the distribution of security cameras. b) Point out the location of alarm systems, closed-circuit television, and video surveillance systems, and security technologies, where monitors are located, who reviews them, as well as operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Periodic and random reviews of recordings must be carried out. Indicate how they review them randomly, weekly, special events, restricted areas, etc., who the designated personnel are, and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept (it must be at least sixty days). e) Alarm systems, closed-circuit television, and video surveillance systems, and security technologies must have an alternative energy source that allows them to continue functioning in the event of an unexpected loss of direct power. Therefore, indicate whether alarm systems, closed-circuit television, and video surveillance systems, and security technologies are backed up by an electrical power plant or some other mechanism to supply electricity, which guarantees their functioning. These systems should have an alarm/notification function, indicating a malfunction and/or recording condition; indicate if your systems have this function. f) Indicate if, in addition to alarm systems, closed-circuit television, and video surveillance systems, you use any other type of technology to strengthen the security measures you already have. g) Describe the procedure implemented to regularly test and inspect alarm systems, closed-circuit television, and video surveillance systems, and security technologies, and ensure their proper functioning. The results of the inspections and functional tests must be documented, as well as necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. h) Indicate if the provider of alarm systems, closed-circuit television, and video surveillance systems, has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
3.1 Security personnel. The strategic supervised premise must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities and merchandise during its transport and handling within the company, as well as for controlling the access of all persons to the building. Security personnel must have a documented procedure to carry out their functions and have full knowledge of the mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the facility. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel and ensure you include the following points: a) Indicate the number of security personnel working in the premise. b) Point out the positions and/or functions of the personnel and operating hours. c) In case of hiring an external service, provide the general data of the company (Tax ID/RFC, legal name, address), and specify the number of employed personnel, operational details, records, reports, etc., that they use to perform their functions. d) In case of having armed personnel, describe the procedure for the control and safeguarding of weapons.
3.2 Employee identification. Management or the premise's security personnel must properly control the delivery and return of badges, ID cards, and/or employee identification credentials. Procedures for the delivery, return, and change of access devices (for example, keys, badges, and/or credentials, proximity cards, etc.) must be documented. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: a) Identification mechanisms (badge and/or credential with photo, access control, biometrics, proximity cards, etc.). b) How contracted personnel by a business partner, working within the facilities (contractors, subcontractors, in-house services, merchandise handling company personnel, etc.), are identified. c) The procedure must also describe how the premise delivers, changes, and withdraws employee identification and access controls, and ensure you include the responsible areas for authorizing and administering them. d) Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for the control of identifications.
3.3 Visitor and supplier identification. To access the facilities, visitors and suppliers must present official identification with a photo for documentation purposes upon arrival, and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by premise personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place. This procedure must be documented. For the case of suppliers and users who work regularly in the premise, the company must have a physical validation system for identification badges in accordance with the control guidelines established by the customs office of their jurisdiction to grant entry and exit authorizations, if applicable.
Response: Explanatory Notes: Describe the procedure for controlling access by visitors and suppliers; ensure you include the following points: a) Point out what records are kept (personal forms for each visit, logbooks). b) The visitor and supplier record must include the following:
3.4 Procedure for identifying and removing unauthorized persons or vehicles. The strategic supervised premise must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles; this procedure must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: a) Responsible personnel. b) Designate a person or area responsible for being informed of security incidents. c) Instructions for confronting and addressing unidentified personnel. d) Indicate in which cases the corresponding authorities must be notified. e) How security incidents and measures adopted in each case are recorded.
3.5 Courier and package deliveries. Courier and package deliveries intended for the personnel of the strategic supervised premise must be examined upon arrival and before being distributed to the corresponding areas. Likewise, the premise must have a documented procedure for the receipt and review of courier and package deliveries, which must be communicated to responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and package deliveries and ensure you include the following: a) Personnel in charge of carrying out the procedure. b) Indicate how the courier and package service provider is identified (indicate if an additional procedure to the supplier access procedure is required). c) Point out how the review of courier and/or packages is carried out, what mechanism is used, what records are kept, and, if applicable, detected incidents. d) Describe the characteristics or elements to determine what courier and/or package is suspicious. e) Point out what action is taken in the case of detecting a suspicious package.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of business partners must include indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any business partner leads to substantial doubts about the veracity of their operations or services, the premise must avoid their hiring and, if applicable, notify their security specialist or Authorized Economic Operator Program contact and the corresponding authority about their suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new business partners and monitoring of partners already working with them; this comprises any type of provider that has a commercial relationship with the premise (with its logistics process, with the supply chain, as well as with potential and predominant clients of frequently hiring their service and/or those who have a commercial relationship with your company); ensure you include the following points: a) What information is required from your business partner. b) What aspects are reviewed and investigated. Indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a business partner is not reliable, thus carrying out a deeper investigation and evaluating whether to work with them. c) Indicate whether you maintain a physical or electronic file for each of your business partners, as well as the information it must contain. d) Point out how the services of your business partner are evaluated and what points you review. The file must include at least the following: a) Company data (name, Tax ID/RFC, activity, etc.). b) Legal representative data. c) Proof of address. e) Commercial references (if applicable). f) Contracts, agreements, and/or confidentiality agreements, security policies. g) If applicable, certificate or certification number in the security programs to which they belong.
4.2 Security Requirements. The strategic supervised facility must have a documented procedure in which, based on its risk analysis, it requests additional security requirements from those commercial partners involved in the service provided by the strategic supervised facility, as well as from service providers that similarly intervene in the control, handling, transport, and/or coordination of merchandise subject to foreign trade, such as: transport, warehouses, service providers for cleaning, private security, personnel hiring, installation and maintenance of alarm and closed-circuit television and video surveillance systems, Information Technology system providers, cargo loading, unloading and maneuver service providers, collection and recycling, contractors, among others). The requirements must be based on the Profile of the Strategic Supervised Facility established by the AGACE, or, if it exists, the specific Profile for each actor in the supply chain corresponding to them. The company must request documentation from its commercial partners that certifies and proves compliance with the minimum security standards established in this Profile of the Strategic Supervised Facility, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation supporting compliance with the requirements established in the Authorized Economic Operator Program. Similarly, the facility must take into account and be aware of the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of the facility's commercial partners who provide their services within the facilities, they must be obligated to comply with these supply chain security requirements. Response: Explanatory Notes: Describe the procedure indicating how you carry out the identification of commercial partners that require compliance with minimum security standards. Ensure you include the following points: a) Indicate if you have a registry of commercial partners that must comply with security requirements, and mention what type of providers these are (transporters, warehouses, security companies, customs agents, companies authorized to provide cargo loading, unloading and handling services, etc.). b) Indicate the documentary form (agreements, accords, contractual clauses, and/or addenda) by which you ensure that your commercial partners comply with security requirements. c) Indicate if there are agreements, accords, contractual clauses and/or addenda regarding the implementation of security measures with your service providers inside the facility, such as: private security, cafeteria, landscaping, cleaning and maintenance services, Information Technology providers, etc. d) Indicate if you have commercial partners to whom membership in a supply chain security program is required (for example: CTPAT, or any other World Customs Organization Authorized Economic Operator Program), as well as the information and documentation requested of them.
4.3 Commercial Partner Reviews. The strategic supervised facility, through the Security Committee, must carry out periodic security evaluations (as well as those derived from risk situations) of the processes and installations of business associates based on a risk analysis, to ensure they have the minimum security standards required by the facility based on the Authorized Economic Operator Program, maintain records of them, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the company must communicate them to its partner or supplier and provide a justified period to address the observations or areas for improvement identified, or otherwise, have the necessary measures to sanction them. Conducting security evaluations of commercial partners is important to ensure that a solid security program exists and functions correctly; therefore, in addition to a documented procedure, there must be a program or calendar for the execution of these security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company is unaware of whether the processes and installations of its commercial partners function correctly, it puts its supply chain at risk. Response: Explanatory Notes: Describe the procedure for conducting evaluations to verify security requirements (processes and installations) of your commercial partners; ensure you include the following points: a) The frequency with which visits to the commercial partner are made (these must be at least once a year and derived from risk situations). b) Program or calendar for the execution of security reviews. c) Record or report of the verification and, if applicable, the corresponding follow-up. d) The verification format(s) must be properly filled out, including the date, name and position of those participating in the review, signatures, etc. e) Indicate what action measures are taken in case commercial partners do not comply with the established security requirements. f) In case of having commercial partners with CTPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed, how it is recorded, and the actions taken in case it is detected that it is suspended and/or cancelled, in accordance with what is established in your procedure. The procedure must include: a) Frequency of visits. b) Security review points. c) Preparation of reports. d) Feedback and agreements with the commercial partner. e) Follow-up on agreements. f) Measures in case of detecting non-compliance with requirements. g) Record of evaluations. h) Area or person responsible for carrying out this procedure.
5.2 Warehouses and Distribution Centers. In case the strategic supervised facility has commercial partners that provide any warehouse, distribution center or other services within its facilities, they must be subject, according to their characteristics, to what is established in this document, with the objective of maintaining integrity in its supply chain. Response: Explanatory Notes: According to the mapping of its logistical process, if foreign trade merchandise is transferred or moved to another warehouse and/or alternative or different distribution center that operates under its authorization as a strategic supervised facility, it must indicate if they are registered under its Tax Identification Number (RFC), providing their general data (name and address) and briefly explaining what activity is carried out in that or those installations (cross dock, temporary warehouse, etc.). Likewise, indicate if these belong to the company or is a service contracted through a third party and/or are part of a shareholder group. In this case, according to the supplier selection criteria mentioned in the Commercial Partners section of this document, indicate how you ensure compliance with minimum security requirements. Facilities that have Strategic Supervised Facility authorization must coincide with the number of Profiles presented, as well as indicate all addresses registered under the RFC. 5.3 Cargo Delivery and Receipt. The strategic supervised facility must ensure the identification of transport medium operators who carry out the collection, delivery or receipt of foreign trade merchandise inside or outside its facilities, warehouses and/or distribution centers. Likewise, the facility must designate the responsible area to supervise the loading or unloading of the shipment, even in accordance with instructions received from clients for its handling and transport. On the other hand, the company must verify the detailed description of the merchandise, weight, labels, marks and quantity, comparing this information with the corresponding legal and customs documentation. The strategic supervised facility, in accordance with its risk analysis, must have a process for the release and extraction of merchandise, establish parameters to inspect and verify through mechanisms, tools or non-intrusive technology available, the foreign trade merchandise to be dispatched, independent of the official reviews that authorities may carry out with the purpose of identifying illicit, prohibited, undeclared merchandise or with discrepancies, including those that, according to their nature, are subject to additional regulations or restrictions for customs compliance and transport. Similarly, it must guarantee that the driver transporting foreign trade merchandise, during delivery or receipt, has the required documentary information for its transport, which includes, destination, route to be maintained, contact data and/or procedure in case of any incident or inspection by any authority, among others. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to ensure that these areas remain free of visible pest contamination. During the loading and unloading process of merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise or pests) and register this review (incident reports, records, reports, etc.) as evidence that the high-security seal and/or lock was placed correctly; digital photographs must be taken at the time of loading the vehicles. To the extent possible, these images should be sent electronically to the destination or delivery contact point of the merchandise for verification purposes. Also, the personnel responsible for the shipping and/or receiving area must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on the identification of common errors in export shipment documentation, with the objective of preventing these from resulting in security incidents or suspicious merchandise.
Response: Explanatory Notes: Attach the documented procedure indicating the procedure for cargo delivery and receipt and ensure it includes the following points: a) Method to identify transport operators. b) Documentation delivered to operators. c) Person responsible for supervising the loading or unloading of the merchandise and checking the information. In addition to transport documents and customs documents (Bill of Lading, manifests, etc., which must be presented to the authority in a timely manner), there must be a record accompanying the entry and exit of merchandise, which includes:
Response: Explanatory Notes: Attach the documented procedure to monitor internal transfers in the strategic supervised facility of foreign trade merchandise. This procedure must include, among other aspects according to its operation: a) Have GPS whose external hardware is hidden and that can resist attempts to remove it; indicate the type of system implemented, if any, and the consultation tools available to monitor the merchandise. b) Identification of estimated transfer times and maneuvers in strategic supervised facilities according to the transport involved. c) Detail the communication means available. d) In case the tracking is carried out by a third party, indicate who is responsible and how it is verified that it is being carried out correctly, in accordance with the procedures the company specifies. 5.5 Cargo Discrepancy Report. There must be documented procedures that describe measures and actions to identify, detect and report measures and/or actions to be taken in case of missing, surplus, prohibited, illicit, undeclared merchandise during handling and transport in the supervised facility or any other discrepancy in the delivery or receipt of containerized, consolidated and/or de-consolidated merchandise prior to complying with customs clearance formalities or those that by their nature put the security of users at risk, which could be during the following processes: receipt, delivery, storage, prior reviews, consolidations, de-consolidations, transport medium yards and, if applicable, according to the services offered with the purpose of having information that aids the corresponding investigations by authorized consignees and, if applicable, by competent authorities. Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies in the delivery or receipt of merchandise and ensure it includes the following points: a) Persons responsible for carrying out the review. b) Documents to be checked. c) Areas to which the information is reported. This procedure must apply both to merchandise received from import; if applicable, in the review at intermediate points; as well as in the final delivery of merchandise to its client.
5.6 Processing of cargo information and documentation. The strategic supervised premise must have documented procedures to ensure that the electronic and/or documentary information used during the movement, storage, custody, handling, and clearance of cargo, as well as the information received from business associates, is legible, complete, accurate, reported in a timely manner, and protected against changes, loss, or the introduction of erroneous information. Similarly, forms and documentation related to import and/or export should be secured to prevent unauthorized use. Response: Explanatory Notes: Describe the procedure for processing cargo information and documentation, ensuring you include the following points: a) Detail how you transmit relevant information and documentation regarding the transfer of your cargo to all parties involved in your supply chain (indicate if you use a specific computer control system and briefly explain its function). Furthermore, detail how you validate that the provided information is legible, complete, accurate, reported in a timely manner, and protected against changes, loss, or the introduction of erroneous information. b) Similarly, forms and documentation related to import and/or export should be secured to prevent unauthorized use. c) Indicate how business associates transmit information to the strategic supervised premise and ensure its protection.
5.7 Inventory management, control of packaging, container, and packing materials. The strategic supervised premise must have documented procedures for automated inventory control, in accordance with its authorization to provide services for the handling, storage, and custody of foreign trade merchandise. These procedures must also include abandonments, destructions, among others, in accordance with applicable regulations, and conduct periodic reviews. Additionally, it must have a documented procedure for controlling the packaging, container, and packing materials of the merchandise, which must also include the procedure for controlling, disseminating, and preventing visible pest contamination, in the case of using wooden packing materials (such as pallets, boxes, crates, cages, spools, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo throughout its entire supply chain. Response: Explanatory Notes: Attach the documented procedure for inventory management. This must include, according to your operation, among other aspects, the following: a) Mention what type of system you use for information exchange with the authority for inventory purposes and your clients. b) Who is your supplier. c) Indicate if you have a contingency plan in case of system failures. d) Mention where it is physically located and who are the responsible parties for its operation. e) The frequency with which you carry out stock verification (Periodic Inventory). Indicate if there is a documented scheduled calendar to perform them or in accordance with the operational provisions of your clients. f) Indicate what is done in the case of surpluses and shortages in inventories and communication with your clients. g) Indicate the treatment given to the control and handling of packaging, container, and packing materials, which must also include the procedure for controlling, disseminating, and preventing visible pest contamination, in the case of using wooden packing materials (such as pallets, boxes, crates, cages, spools, dunnage, chocks, supports, or platforms) to stack, move, and protect the cargo. h) This point is also focused on reducing the risk of introducing or disseminating quarantine pests of importance to the country through packaging (imports); therefore, describe how you comply with the provisions established by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144-SEMARNAT-2017, in accordance with International Standard for Phytosanitary Measures No. 15, known as Regulation for Wood Packaging Material used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. i) Indicate how the fumigation process is carried out to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions do you take if quarantine of packing materials is required? j) Indicate the area responsible for carrying out this process, as well as the documentation or certificates obtained. The applicant's procedures may include: a) Warehouse only accessible to authorized personnel. b) Control of incoming merchandise, transfers to other warehouses, consolidation or de-consolidation. c) Actions taken if irregularities, discrepancies, losses, or thefts are identified. d) Treatment of deterioration or destruction of merchandise. e) Separation of various types of merchandise, for example, high-value, hazardous.
Customs Management. The strategic supervised premise must have documented procedures in which internal and operational policies are established, as well as the necessary controls for the due compliance of customs obligations. 6.1 Customs Clearance Management. The strategic supervised premise must have a documented procedure in which criteria are established for the selection of a customs broker or, in their case, a customs attorney, who, in accordance with national legislation, are authorized to promote on behalf of others the clearance of merchandise. Response: Explanatory Notes: Describe the selection and evaluation procedure of the customs broker/attorney and ensure it includes the following points: a) Selection criteria. b) Evaluation methods and periodicity. c) Describe the indicators with which you evaluate the service of customs brokers. Indicate the full name and the patent number and/or authorization of the customs broker or attorney authorized to promote your foreign trade operations. 6.2 Customs Obligations. The strategic supervised premise must have a documented procedure that establishes how it maintains updated control of the automated inventory of foreign trade merchandise and online with the authority in a permanent and uninterrupted manner, in accordance with what is established in Article 59, fraction I, of the Law and the information referred to in rule 4.8.3. and Annex 24. Additionally, it must include at least the following: a) the process to comply with security measures, control, surveillance, access routes, infrastructure, and surface equipment; b) processes related to equipment for expediting customs clearance relative to electronic systems for the control of merchandise, persons, or vehicles that enter or leave the premise. The foregoing in accordance with provisions specific to its authorization. On the other hand, it must include in the procedure the process for the destruction of waste or destination in the national market or loss of merchandise in accordance with current regulations, transfers of merchandise to supervised and/or strategic premises, transfers for maintenance, repair, or calibration of machinery and/or equipment. Response: Explanatory Notes: Attach the procedure to comply with your customs obligations. Attach the procedure(s) for compliance with what is established in rules 1.5.3., 1.6.13., and 1.6.17., as applicable. 6.3 Customs Verification. The strategic supervised premise, in order to verify the truthfulness of the information declared in its name before the competent authorities, must have documented procedures so that the personnel designated by the company periodically verify that the customs declarations registered in its accounting match what appears registered in SAAI Web and, if applicable, report to the customs authority any discrepancy in said information. The company, likewise, must have a procedure for archiving customs declarations for their adequate control. Response: Explanatory Notes: Attach the procedure established to verify the information registered in SAAI Web, and cross-check with the customs declarations and documentation requested from the customs broker and/or customs representative.
Security of cargo vehicles, containers, trailers, and/or semi-trailers. The security of transport means, tractors, containers, trailers, and semi-trailers (including pickup trucks, vans, or vans, among others) must be maintained to protect them from the introduction of unauthorized persons and/or materials. For this reason, it is necessary to have documented procedures to inspect, seal, and maintain their integrity. Similarly, the inspection process of said transport means, containers, train cars, trailers, and semi-trailers used as Instruments of International Traffic must include an agricultural inspection procedure to look for visible pests and serious structural deficiencies. Pest contamination is defined as visible forms of animals, insects, or other invertebrates (living or dead, at any stage of the life cycle, including eggs, etc.), or any organic material of animal origin (including blood, bones, hair, meat, secretions, excretions, etc.); plants or plant products (including fruits, seeds, leaves, twigs, roots, bark, etc.); or other organic material, including fungi, soil, or water; when such products are not the declared cargo within the Instruments of International Traffic. In the event of using high-security seals, it is necessary to have procedures to correctly seal and maintain the integrity of containers and trailers from the moment they leave your facilities. A high-security seal must be applied to all containers and trailers for foreign trade shipments, which must meet or exceed the ISO 17712 Standard for high-security seals. With the objective of maintaining supply chain security, the strategic supervised premise must inspect all cargo vehicles systematically upon entry and exit from its facilities (domestic and international traffic), in addition to keeping a record. 7.1 Use of seals and/or padlocks on containers. The strategic supervised premise, if applicable, must identify the cargo transport means owned or subcontracted that transport foreign trade merchandise that may be: maritime, air, national land, cross-border, railway, and/or multimodal, which are subject to the placement of seals and/or padlocks to meet or exceed the ISO 17712 Standard with the aim of guaranteeing at all times the integrity of the cargo. For this reason, as one of the security mechanisms, the strategic supervised premise, if applicable, must use high-security padlocks or seals that meet or exceed the ISO 17712 Standard in all containers and loaded trailers that are subject to foreign trade and maintain their integrity until delivery at the final destination. For this, the premise must have documented procedures to place and verify the correct application of seals, their inspection at intermediate points, final destination, and their replacement when opened by any authority. In the event of such an inspection, drivers must notify and register any anomaly or unusual structural modification found in the transport means resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to the business partners involved in the supply chain, and the investigation of the security incident; these must be notified to security personnel, business partners who may be part of the affected supply chain, security specialist, or Authorized Economic Operator Program contact. Likewise, it is necessary to have a documented procedure for their administration that includes control, assignment, safeguarding, handling of discrepancies, and destruction of seals and padlocks (the latter is mandatory whenever seals are broken in your facilities). Regarding the supplier of the seals and/or padlocks, it must be demonstrated how these comply with the ISO 17712 Standard. The company's management or a security supervisor must carry out periodic and documented audits of the high-security seals and/or padlocks; these reviews must include the verification of the inventory of stored seals and/or padlocks and the cross-check with inventory records and shipping documents. Also, the supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the transport means and Instruments of International Traffic to corroborate that the information is correct. For this case, the strategic supervised premise must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or padlocks on the transport means that transfer foreign trade merchandise in accordance with its logistics process and in those traffics that require it due to their high probability of occurrence and impact of the identified risk and during maneuvers in the premise. In it, it must evidence controls that allow accrediting that it supervises the portability of seals and/or padlocks resulting from entries or exits of the strategic supervised premise in the transport means. In all cases, it must use the VVTT inspection method to mitigate improper manipulations as follows: a) V - View the seal and lock mechanisms of the container. b) V - Verify the seal number. c) T - Pull the seal to ensure it is correctly placed. d) T - Twist and turn the seal to ensure it.
Response: Explanatory Notes: List, according to your risk analysis and logistics process, the transport means that are subject to the placement of high-security seals and/or padlocks. Attach the documented procedure for the supervision of the placement and review of seals and/or padlocks on the vehicles, transport means, containers, trailers, and/or semi-trailers that transport foreign trade merchandise. This must include, among other aspects according to your operation: a) The use of seals and/or padlocks that meet or exceed the ISO 17712 standard. b) If applicable, use the VVTT inspection method. c) Review and cross-check the documentation containing the original seal or padlock number for purposes of entries or exits of strategic supervised premises. In the event of using a replacement seal and/or padlock, said number must be registered within the control of the strategic supervised premise. If altered seals and/or padlocks are identified, they must be kept to help carry out the investigation of said incident or discrepancy. d) Indicate how you assign and replace high-security padlocks, in the case of maneuvers such as prior recognition, replacement, among others. If applicable, attach the documented procedure for the control and handling of seals and/or padlocks; this must include, among other aspects according to your operation: a) What type of seals and/or padlocks you use in your operations (foreign trade, transit, storage, etc.). b) Who has access and how padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (record of seals used, as well as the receipt of new seals and/or padlocks. c) Describe how the company's management or security supervisor participate in audits of high-security seals and/or padlocks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how the supervisors of the shipping area and/or warehouse managers verify seal numbers used in transport means and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). d) How discrepancies in seal and/or padlock numbers are addressed. e) Indicate who the supplier(s) are and how it is proven that the specifications of the seals and/or padlocks comply with the ISO 17712 Standard (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO). All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary. 7.2 Inspection of transport means, containers, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of the transport means container, train cars, trailers, and/or semi-trailers used as Instruments of International Traffic, according to their nature, even the reliability of the locking mechanisms in them with the aim of identifying natural or hidden compartments, as applicable. Inspections of transport means or cargo vehicles, containers, and trailers must be systematic and carried out upon entry and exit from the company and, if applicable, at the merchandise loading point; and if the infrastructure allows, before arriving at the customs office for clearance using the VVTT inspection method, a record of these inspections must be kept in an access-controlled area and carried out in a place monitored by alarm systems and closed-circuit television and video surveillance; said system must cover the inspection process in its entirety. The documented procedure for its inspection must include, by way of example and not limitation, the following review points: Transport Means Trailers, Train Cars, Semi-trailers, and Containers
Response: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of the transport means according to their nature and logistics process involved in the entries and exits of the supervised premise. This must include, among other aspects according to your operation: a) Those responsible for carrying out the inspection. b) Definition of the place(s) where the inspection is carried out and indicate how the monitoring is performed by alarm systems and closed-circuit television and video surveillance. c) The security review points for transport means, trailers, semi-trailers, containers, railway transportation, and/or multimodal according to official provisions and agricultural inspections with the aim of looking for visible pests. Attach the format for the inspection of transport means or cargo vehicles, containers, train cars, trailers, and/or semi-trailers. If you use other types of cargo vehicles for the transport of your merchandise (vans, pickups, 3.5 tons, tankers, etc.), your procedure and inspection format must include the process and review points. Likewise, the security and agricultural inspection format must include the following information: a) Date of inspection; b) Time of inspection; c) Vehicle license plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected; and, f) Name of the employee who performs the inspection and the supervisor. The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation. The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
In the event that it is deemed necessary, the inspection format for cargo vehicles may be part of the shipping documentation. Additionally, based on risk analysis, the company should conduct random reviews of transport means after transport personnel have performed inspections of transport means to verify that they have been carried out correctly, counteract internal conspiracies, and prevent security incidents.
The reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different places where the transport means may be susceptible to contamination.
7.3 Storage of vehicles, transport means, containers, train cars, trailers, and semi-trailers. In the event that the transport means, containers, trailers, and/or semi-trailers that will be destined to transport foreign trade merchandise are empty and must be stored in parking areas, they must be secured with a lock and/or indicative seal, or in their case, in a safe area that is guarded and/or monitored.
When it is necessary to store any loaded container, trailer, and/or semi-trailer, it must be located in a safe area that has physical barriers and is monitored by alarm, closed-circuit television, and video surveillance systems, to prevent unauthorized access and manipulation of the merchandise, so it must be closed with a high-security lock in accordance with ISO 17712 Standard.
Response: Explanatory Notes: Indicate whether the company stores containers, trailers, and/or semi-trailers for subsequent dispatch, or in their case, those that are empty and how it maintains their integrity within its facilities. a) In the event of using locks and/or seals, indicate what type you use. b) In the event of using any containers, trailers, and/or semi-trailers as storage for raw material and/or any other type of merchandise, indicate how it maintains their integrity and security.
Additionally, there must be continuous training programs for personnel to disseminate the security policies of the premises, as well as the consequences and actions to be taken in the event of any breach or security incident.
8.1 Employment background verification. The strategic customs-supervised premises must have documented procedures to investigate and verify the information stated in the curriculum vitae, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either on their own or through an external company.
Similarly, for positions that require it due to their sensitivity and affect the security of shipments subject to foreign trade, in accordance with their previously conducted risk analysis, they must consider requesting stricter requirements for hiring, which must be carried out periodically. Regarding personnel already working in the company, periodic investigations must be conducted based on the activities and/or sensitivity of the employee's position.
All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for hiring personnel, and ensure you include the following: a) Requirements and documentation required. b) Tests and exams requested. Indicate the areas and/or critical positions that have been identified as risky, according to your analysis, and indicate the following: a) Indicate what the additional requirements are for specific areas and/or job positions, such as criminal records (if local legislation and company policies allow), certificate of non-criminal record, socioeconomic studies, clinical studies, toxicological (drug use) studies, etc. In their case, indicate the positions or work areas where they are required and with what frequency they are carried out. b) Indicate whether, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. In the event of hiring a service agency for personnel hiring, indicate whether it has documented procedures for personnel hiring and how it ensures they comply with the same. Explain briefly what they consist of. The procedures for personnel hiring and contractors may include: a) Thorough investigations of the work and personal backgrounds of new employees. b) Confidentiality and liability clauses in employee contracts. c) Specific requirements for critical positions. d) In their case, the periodic update of the socioeconomic and physical/medical study of employees who work in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. The premises may consider the results of background verifications of candidates, as allowed by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel dismissal procedure. Documented procedures must exist for personnel dismissal, which must include the delivery of identification, and any other item that has been provided to perform their functions (keys, uniforms, badges and/or credentials, IT equipment, passwords, tools, etc.). Likewise, this procedure must include the deactivation in IT systems and access controls, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel dismissal, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the delivery of identification, access controls, and other equipment is carried out and confirmed. c) Indicate the control record and/or format, in which the delivery of material and deactivation in IT systems (in their case, attach) is identified and ensured. d) Indicate the type of records of personnel who ended their employment relationship with the company, so that in case it was for security reasons, their service providers and/or business associates are prevented.
8.3 Personnel administration. The strategic customs-supervised premises must maintain an updated system, control, or database of active employees. Likewise, it must carry out and maintain updated records of affiliation to social security institutions and other legal labor records.
In the event that the company has personnel hired by its business partners and works within the facilities, it must ensure that they comply with the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate whether the premises has an updated system, control, or database, both of personnel employed directly, as well as that hired through a service provider company, and ensure it includes, among others, the following points: a) Full name. b) Updated photograph at least every five years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). d) Affiliation. e) Work background. f) Diseases. g) Medical exams. h) Training. i) Results of periodic evaluations. j) Observations. This personnel must be hired in accordance with current labor laws and regulations.
9.1 Document classification and handling. Procedures must exist to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified and procedures established for its destruction. The company must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: a) Control register for delivery, loan, among other documents. b) Restricted access to the archive area. c) Storage and classification policies. d) An updated security plan that describes the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. e) In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. 9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts that require periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards, which must be communicated through a training program for all employees who handle computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must use secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when they are outside the office, as well as procedures designed to prevent unauthorized remote user access.
For the above, there must be written procedures and infrastructure to protect the company against loss, theft, leakage, hacking, and/or ransomware of information, this includes the procedure for the recovery (or replacement) of IT systems and/or data, as well as a system or software established to identify the abuse of information technology systems and detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
If a data leak or other unexpected event occurs that results in the loss of data and/or equipment, the procedures must include the recovery or replacement of IT systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery or replacement of IT systems and/or data, which includes how it backs up and ensures the security of its information, in addition to protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which information backups are carried out. b) Who has access to them and who authorizes the recovery of information. c) Indicate what type of tests it performs and how often, to verify the security of the network, systems, and infrastructure. d) Mention if, to carry out this type of tests or vulnerability scans, it does so through software, a third party or provider, and in its case, indicate the name or corporate name. e) In the event of finding vulnerabilities, describe the corrective actions that must be implemented. f) Indicate if it shares information about cybersecurity threats with its business partners that participate within its supply chain (for example: communications, bulletins, emails, etc.). g) Systems must be protected under passwords and must be modified frequently, for which reason indicate the procedure to change them. h) Indicate if there are information security policies for their protection. i) There must be a system or software to detect and identify the abuse, intrusion, or access of unauthorized persons to its systems and/or IT data (any system that is used by the premises), as well as the abuse of the policies and procedures established by the company, including unauthorized access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures, for which reason, indicate the corrective policies and/or sanctions in the event of the detection of any violation of the IT systems and security policies.
Information Technology and cybersecurity policies and procedures must be reviewed annually and updated as a result of an attack or in accordance with situations that may put the premises' systems at risk. Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the premises' intranet remotely when they are outside the office. In the event of allowing employees to use personal devices to perform the company's work, such devices must comply with the premises' cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the premises' network securely. Indicate whether business partners have access to the premises' computer systems. In their case, indicate what programs and how they ensure access control to them. Indicate if the computer equipment has a backup power supply system that allows business continuity. The procedures regarding the backup of the premises' information must also include: a) How and for how long the data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in case of incident and how to recover the information. c) Frequency and location of backup copies and archived information. d) If backup copies are stored in sites alternative to the facilities where the data processing center is located. e) Tests of the validity of data recovery from backup copies. The procedures regarding the protection of the premises' information must also include at least the following: a) An updated and documented policy for the protection of the premises' computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted format. b) Detail if it operates with multiple systems (sites/locations) and how such systems are controlled. c) Who is responsible for the protection of the premises' computer system (responsibility should not be limited to one person, but to several, so that each can control the actions of the rest). d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. For this reason, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to personnel authorized to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or in its case report that access to confidential systems is based on job requirements. e) Indicate the elements or format that passwords for access to Information Technology systems and computer equipment must have, frequency of changes, if there are other authentication methods, and who or what area provides those passwords. f) Indicate the name of the firewall and anti-virus used (include licensing-related information), evidencing that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or with incorrect licenses (software and hardware). All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware that contain confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed properly to avoid information leakage. g) In the event of personnel dismissal, access to computer equipment, telecommunications, and network must be eliminated at the moment of the employee's separation, this includes email accounts, system access accounts, software, programs, etc. h) Measures planned to handle incidents in case the system is compromised.
10.1 Training and awareness on threats. The strategic supervised facility must have a training and awareness program on security policies in the supply chain directed to all its employees (operational and administrative), and additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. Likewise, specific training must be offered according to their functions to help employees maintain cargo integrity, perform container, trailer, and/or semi-trailer reviews for agricultural and security purposes, receive and review mail and packages, prevent operations with proceeds of illicit origin (money laundering, terrorism financing, etc.), how to recognize and report internal conspiracies, protect access controls, as well as training regarding smuggling, cargo theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident, and when there are changes in facility procedures. In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures, and standards (theft, leak, hacking, and/or information kidnapping), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodically maintain update programs. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of training, names of attendees, topics taught, in addition to having measures to verify that the training provided met all training objectives.
Response: Explanatory Notes: Must have a training program on security and prevention in the supply chain for all employees working for the company (administrative, operational, direct and indirect). Briefly explain what the training program consists of and ensure you include the following: a) Brief description of the topics taught in the program. b) When they are taught (onboarding, specific periods, resulting from audits, security incidents, etc.). c) Frequency of training, as well as updates and reinforcement. d) Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, names of attendees, topics taught, in addition to having measures to verify that the training provided met all objectives of the same. e) Explain how employee participation in supply chain security issues is encouraged. Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments. b) Smuggling hidden in natural compartments. c) Signs of pest contamination. d) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit. e) Agricultural review training must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with the International Plant Protection Convention Standard known as Regulation for Wood Packaging Material Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations, and the identification of infested wood.
10.2 Awareness for transport medium operators. The strategic supervised facility must make known to the operators of the transport media used for the transfer of goods destined for foreign trade, the security policies regarding agricultural and security inspection procedures of transport media, loading and unloading, handling of security incidents, change of locks in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of transport media must be trained to inspect cargo vehicles for such purposes. In the case where the transport service is provided by a business partner, you must ensure that operators know all established security policies and procedures.
Response: Explanatory Notes: Describe the dissemination program on security in the supply chain focused on transport medium operators and ensure you include the following: a) Indicate how this dissemination is carried out. b) Point out the topics covered. c) In case of using the services of a business partner for the transfer of your goods, indicate how operators are informed of the facility's security policies and procedures. d) Indicate how participation in supply chain security training of transport medium operators is documented (videos, attendance lists, brochures, etc.). The topics that must include, by way of example and not limitation, are: a) Access and security policies at the facilities. b) Delivery-receipt of goods (including suspicious cargo shipments). c) Confidentiality of cargo information. d) Transfer instructions. e) Accident and emergency reports. f) Instructions for placing high-security locks and/or seals in transit (placing a new one, review after any authorized stop, etc.). g) Installation and testing of security alarms and unit tracking, when applicable. h) Identification of authorized formats and documents to be used. i) Signs of hidden compartments. j) Smuggling hidden in natural compartments. k) Signs of pest contamination. l) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
11.1 Reporting of anomalies and/or suspicious activities. In case of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with your logistical processes, (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be notified to security personnel, business partners that may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of such anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, as well as those that contain mechanisms to anonymously report problems related to security, and ensure you include the following: a) Who is responsible for reporting incidents. b) Detail how you determine and identify with which authority to communicate in different scenarios or presumption of suspicious activities. c) Mention if you keep a record of reporting anomalies and/or suspicious activities and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, as well as the analysis and investigation of security incidents in the supply chain to determine their cause, as well as corrective actions to prevent them from happening again, which must be implemented as quickly as possible. The information derived from this investigation must be documented and available at all times for authorities that so require. This information must include the documentation generated to carry out the foreign trade operation of the affected goods that allows identifying each of the processes the goods went through until the point where the incident was detected and that allows recognizing the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any security incident occurring and ensure you include the following: a) Responsible for carrying out the investigation. b) Documentation that integrates the investigation file. The documents to include in the file derived from the investigation, by way of example and not limitation, may be: a) General information of the shipment, service order. b) Transport request; confirmation of transport medium; identification of transport operator (access records, exit, record of security inspections, etc.). c) Transport medium inspection formats; exit orders; records of collection, delivery, and receipt of foreign trade goods. d) Videos from alarm systems, closed-circuit television, and video surveillance. e) Documentation generated for the carrier (packing list, bill of lading, instruction sheet). f) Documentation generated by and for business partners and customs authorities.
E9. Railway Transporter Profile. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization. General Information The objective of this Profile is to ensure that the railway transport concessionaire company develops and implements security practices and processes that ensure its supply chain, mitigating the risk of contamination in its traction and towed equipment (boxcars, gondolas, hoppers, tank cars, containers, chassis, trailers, platforms, etc., which do not have their own traction and circulate on railway tracks and are used to transport goods inside and in containers) with illicit products, as well as loss or theft of goods and/or any other factor that could compromise supply chain security. Railway transport concessionaire companies interested in obtaining the authorization referred to in rule 7.1.5., must have documented and verifiable processes. Likewise, the railway transport concessionaire company interested in the aforementioned authorization must integrate the criteria required in this document into the model or business design it has established, seeking during the implementation of security standards the application of an analysis culture that supports decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the company itself. During the filling out of this document, those interested in obtaining certification will analyze their logistical processes, identifying risks that affect the supply chain and at the same time providing treatment to reduce these risks. Mainly those related to origin and destination points, routes, facilities, volume of operations, yard security, previous security incidents, and interaction with business partners. Filling Instructions:
You must fill out a Railway Transporter Profile of the main installation and/or terminal where services are generated for export and import, where railway equipment and yards for the storage of containers with foreign trade goods are used and safeguarded.
Describe in detail how the railway transporter complies with or exceeds what is established in each of the sections as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Standard description. 1.1 Sub-standard Sub-standard description Response. Explanatory Notes. Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards, therefore you must attach the procedures in Spanish; these procedures must be characterized by describing or defining the objective the document pursues, the start and end of the process, measurement indicators, requirements, documents or formats to be used, responsible parties, among others. The section regarding Explanatory Notes is a guide regarding the points that must be included in the Response of each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once this Railway Transporter Profile is answered, you must attach it to the Application for inscription in the Certified Business Partner registry referred to in the first paragraph of rule 7.1.5., fraction I, subsection c).
For the purpose of verifying what is stated in the previous paragraph, the SAT through the AGACE may carry out an inspection at the installation indicated here, with the exclusive purpose of verifying what is stated in this document.
Any incomplete Railway Transporter Profile will not be processed.
Any question related to the Application for inscription and the Railway Transporter Profile, direct it to the contacts appearing on the SAT Portal.
In the case of being authorized as a Certified Business Partner, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and as a result changes or modifications are required in the information provided and stated in this Railway Transporter Profile to the authority and presented for renewal, in accordance with what is established in rule 7.2.1., fourth paragraph, fractions I, II, and VII.
When, as a result of the inspection visit, non-compliance related to minimum security standards results, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the indicated non-compliances. Installation Data You must fill out a Railway Transporter Profile of the main installation and/or terminal where services are generated for export and import, where railway equipment and yards for the storage of containers with foreign trade goods are used and safeguarded. Installation Information Railway Transporter Profile Number: of RFC Name and/or Business Name: Name and/or Installation Denomination Installation Type Street Number and/or exterior letter Interior number and/or letter Neighborhood Postal Code Municipality/Delegation Federal Entity Installation Age (years of operation) Predominant Activity Service Type (General/Specialized Cargo): No. of average monthly shipments (EXP): No. of average monthly shipments (IMP): No. of total employees at this installation: Installation Surface (m2):
Certifications in security programs: (Indicate if this facility holds a certification from any of the following programs) CTPAT Yes No CTPAT Account Number (8 digits): ___________________________________ Date of the Last Visit: ____________________ Level: Pre-Applicant: Applicant: Certified: Certified/Validated: Authorized Economic Operator from other countries (AEO) Yes No Program: _______________________________________________________________ Other Supply Chain Security Programs Yes No Program ______________________________
Registration: ____________________
Certifications: (Indicate if you hold certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. The railway transport concessionaire must have measures to identify, analyze, and mitigate security risks throughout the supply chain, including its facilities. For the above, it must develop a written procedure in which risks are determined based on its organizational model (example: volume, units, yards, routes, potential threats, etc.) that allows it to implement and maintain appropriate security measures. Based on the above, the railway company must also have a written process based on its risk analysis to select new business partners and monitor those with whom it is already working. This procedure must be carried out at least once a year, so that it allows identifying other risks or threats in the operation that may arise from the result of an incident or that originate from changes in the company's initial conditions, as well as to identify that the policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the company's Security Committee must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Attach the risk matrix and the documented procedure that you use to identify risks in your daily operations along the supply chain and its facilities, it must include at least the following points: a) Frequency with which this procedure is carried out. b) Indicate which sections, routes and/or areas of the railway transport concessionaire are incorporated into the risk analysis. c) Type of service: Domestic and international transit. Likewise, the documented procedure to identify risks in the supply chain and its facilities, should contemplate the risk assessment and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Identification of risks in your supply chain and its facilities. c) Risk analysis (causes, consequences, probabilities and existing controls to determine the risk level as high, medium, and low). d) Risk evaluation (decision making to determine the risks to be treated and priority for implementing the treatment). e) Risk treatment (application of alternatives to change the probability of risks occurring). f) Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use risk management, governance, and evaluation techniques in accordance with the international standards ISO 31000, ISO 31010, and ISO 28000 that, according to your business model, should be implemented.
1.2 Security Policies. The Railway Transport Concessionaire Company must have policies oriented towards preventing, securing, and recognizing threats to the security of the supply chain and company facilities, such as drug trafficking, arms trafficking, human smuggling, prohibited goods, acts of terrorism, as well as in the exchange of information, reflected and supported in the procedures that apply. To promote a security culture, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The senior officials or executives of the company who must endorse and sign the security policy may include the company president, chief executive officer, general manager, security director, or personnel with equivalent rank with decision-making authority.
Response: Explanatory Notes: State the railway carrier's policy on security oriented towards preventing, securing, and recognizing threats in the supply chain and all of its company facilities, indicate who is the responsible for its review, signature, and dissemination to employees, as well as the frequency with which it is carried out its update. The security policy must be signed by a senior company official and be displayed in various areas of the company, including the website, posters in key areas (reception, shipments, receipts, warehouse, etc.), and as part of initial and reinforcement training.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year that allows evaluating all processes in matters of security in the supply chain in a more critical and deep manner, as well as guaranteeing that its employees follow the company's security procedures. The audits must be carried out by the company's Security Committee and a documented procedure must be established, as well as a program or calendar for its realization. Although it is necessary that the audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, level of risk, business model, and variations between facilities. The audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and guarantee that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of such reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the follow-up and closure of preventive, corrective, and improvement actions identified. The senior management of the organization must review the results of the audits, and undertake the required corrective or preventive actions. The audit review process must guarantee that the necessary information is collected to allow management to make this evaluation. The review must be documented, and the company's Security Committee must provide and register periodic updates on the progress or results of any audit, exercise, or validation. Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain, ensure that you do not exclude the following points: a) Indicate how the company carries out the scheduling or calendarization to carry out an internal audit, in matters of security in the supply chain. b) Indicate who participates in them, and the records that are made of them, as well as the frequency with which they are carried out. c) Indicate how the company's management verifies the result of the audits in matters of security, how it carries out and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure of the same. d) The formats used during internal audits must be properly filled out, and through them, evidence that the procedures and measures of security are being put into practice.
1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity, incidents of any kind that affect the normal development of the operations of the railway transport concessionaire company. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, a customs closure, a bomb threat, the detection of suspicious packages, a power outage, theft and/or damage to goods, threats or extortion, blockades or road closures, among others. Such plans must be communicated to administrative and operational personnel through periodic training, as well as carrying out tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness, from which a properly filled-out and signed record must be maintained (for example: result reports, minutes, or reports, which must be backed up by video recordings, photographs, etc., that demonstrate their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level. Response: Explanatory Notes: Attach the procedure or contingency and/or emergency plan focused on the supply chain and its facilities, relating those risk events that can affect the functioning of the carrier such as accidents during the route (derailments, fires, run-overs, blockages, robberies, accidents, mechanical failures, customs closures, etc.) to ensure the continuity of the business. This procedure must include, by way of illustration and not limitation, the following: a) What situations it contemplates, describing the plan of action and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. b) What mechanisms it uses to disseminate and ensure that these plans are effective. c) Contemplate the scheduling and carrying out of tests, practical exercises, and annual drills and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., that demonstrate their execution). In the case of transporting Hazardous Materials and Waste, an emergency sheet must be attached that indicates the actions to be taken in case of incident or accident (leaks, spills, explosions, fires, etc.).
2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the case of having detected an irregularity, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal routes, and the location of buildings must be fully identified. Response: Explanatory Notes: Indicate the predominant materials with which the facilities are constructed (for example, metal structure and sheet metal walls, brick walls, wood, among others) and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damages to the facilities. Attach a general distribution or architectural plan, where the limits, access routes, parking, critical areas, boundaries, and the location can be identified, yards of the classification of the terminal railway.
2.2 Access at Gates and Booths. The entrance or exit doors of vehicles and/or personnel accessing railway operation yards and/or administrative offices must be attended and/or supervised either by means of own personnel or a private security company. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks. Response: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each one, and indicate how they are monitored (in case of having assigned personnel, indicate the quantity). Detail if there are blocked and/or permanently closed doors and/or accesses. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls that you use).
2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the company's parameters, based on a risk analysis. These must be inspected regularly and keep a record of the review with the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks. In the case of providing storage services for railway cars, this zone must be clearly delimited, identified, and monitored according to the service required (national or international, as well as high value and dangerous) to prevent unauthorized entry. Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls with which the company has, ensure that you do not exclude the following points: a) Indicate the characteristics of the same (material, dimensions, etc.). b) In case of not having fences, justify in detail the reason. c) Frequency with which the integrity of the perimeter fences is verified, and the records that are kept for the purpose of ensuring their integrity and identifying damages, which must be repaired as soon as possible. d) Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages. e) Indicate how your railway operation yards are divided. f) Briefly describe, how you separate railway cars or domestic and/or international cargo containers, empty, under repair and/or maintenance, workshops, among others. The procedure for the inspection of the perimeter fences could include: a) Personnel responsible for carrying out the process. b) How and how often the inspections of the fences, perimeter fences, and/or peripheral barriers and buildings are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that the repairs and/or modifications comply with the technical specifications and security requirements necessary.
2.4 Parking. Access to the parking lots of the facilities must be controlled and monitored by security personnel or designated for this task. It must be prohibited that private vehicles (employees, visitors, suppliers, and contractors, among others) park within the operational areas of handling and storage of traction and towed equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that circulate on railway tracks and that are used to transport merchandise inside and in containers), as well as in adjacent areas. Response: Explanatory Notes: Describe the procedure for the control and monitoring of the parking lots, ensure that you do not exclude the following points: a) Those responsible for controlling and monitoring access to the parking lots. b) Identification of the parking lots (specify if the employee parking, visitor parking, is separated from the traction and towed equipment, (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that circulate on railway tracks and that are used to transport merchandise inside and in containers) and handling of merchandise. c) How entry and exit control of vehicles to the facilities is carried out. Indicate the records that are made for parking control and the existing control mechanisms, (for example: badges, card readers, lanyards, etc.), how they are assigned and the responsible area for doing so. d) Policies or mechanisms to not allow the entry of private vehicles to the storage areas of means of transport and in case of handling of merchandise.
2.5 Key and Lock Device Control. According to the risk analysis, windows, doors, and inner and outer fences must be secured with locking devices. The railway carrier must have documented procedures for the handling, safeguarding, assignment, and control of keys in the facilities of the inner areas that have been considered critical, keeping a record and establishing signed responsibility letters from the persons who have keys or authorized access according to their level of responsibility and work within their work area. The management of the railway transport concessionaire company will be responsible for controlling the keys of the sensitive or restricted areas of its facilities.
Response: Explanatory Notes: Indicate if all doors, windows, inner and outer entrances have closing or security mechanisms. Attach the documented procedure or procedures for control, safeguarding, assignment, and handling of the keys of the facilities, offices, and inner areas. Ensure that these procedures do not exclude the following points: a) Those responsible for administering and controlling the security of the keys. b) Format and/or control record for the loan of keys. c) Treatment of loss or non-return of keys. d) Indicate if there are areas where access is granted with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow clear identification of people, material, and/or equipment located there, including the following areas: entrances, exits, parking areas, repair and maintenance yards, rolling stock, perimeter and/or peripheral fences, inner fences, loading and unloading, etc. An emergency and/or backup system must be available in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure that you include the following points: a) Indicate which areas are illuminated and which have a backup system (indicate if you have an auxiliary power plant) or any other mechanism to supply electricity in case of any contingency. b) How you ensure that the lighting system is appropriate in each of the areas of the company, in such a way that it allows a clear identification of the personnel, material, and/or equipment that it covers. c) Responsible for the control and maintenance of the lighting systems. d) Maintenance and review program (in case of coinciding with another process, indicate it). The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting.
2.7 Communication devices. The railway transport concessionaire company must have devices and/or communication systems in order to have immediate contact with security personnel and/or emergency and security authorities in case they are required. Additionally, a backup communication system must be available and its proper functioning verified periodically.
Response: Explanatory Notes: Describe the procedure that personnel must follow to contact security personnel or, in their case, the corresponding authority in the event of any incident. Indicate whether operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons) to communicate with security personnel and/or the relevant party (these must be accessible to users, to ensure a prompt response). Indicate what communication devices are used by the security personnel of the railway transport concessionaire company (landline phones, cell phones, radios, alarm system, etc.). Describe the procedure for the control and maintenance of communication devices, ensuring not to exclude the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate whether backup communication devices are available in case the system fails permanently, and if so, detail briefly. d) Indicate whether the company's crew uses phones, radios, cell phones, civil band (CB), or any other means for internal communication and the policies for their assignment. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Record of verification and maintenance of devices. c) Method of assignment of communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance. Alarm systems, closed-circuit television, video surveillance, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other considered sensitive areas, notify the corresponding area, and also be used as evidence in investigations derived from any incident. These systems and security technologies must be installed, monitored, and supervised according to a prior risk analysis so that areas involving the access of personnel, visitors, suppliers, cargo loading/unloading, and cargo vehicles are kept under surveillance and monitoring, as well as considered sensitive areas, and additionally, areas where traction and towing equipment are normally located (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction that circulate on railway tracks and are used to transport merchandise inside them and in containers). Such systems must allow clear identification of the area or environment being monitored, be permanently recording, and maintain a backup of recordings for at least one month, considering that, in the case where their logistics processes exceed this period, the backup retention period must be increased, in order to have the necessary elements to assign corresponding responsibilities in the event of a security incident. Alarm systems, closed-circuit television, video surveillance, and security technologies must have a documented operational procedure that includes supervision of the equipment's good condition and verification of the correct position of cameras, indicating the frequency with which recordings must be backed up, as well as those responsible for their operation. Such systems and all security technology infrastructure must have restricted access.
Response: Explanatory Notes: Mention the procedure indicating the functioning of the external central alarm system or sensors, and if applicable, describe the following points: a) Indicate whether doors and windows have alarm sensors or motion sensors. b) Procedure to follow in case an alarm is activated. Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensuring to include the following points: a) Indicate the number of cameras of the alarm and closed-circuit television/video surveillance systems installed, technical characteristics, and their location (detail if it covers entry and exit points of the facilities, to cover the movement of vehicles and individuals, as well as vehicle storage areas). b) Point out the location of alarm systems, closed-circuit television, video surveillance, and security technologies where monitors are located, who reviews them, as well as operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Periodic and random reviews of recordings must be carried out. Indicate how they are reviewed (random, weekly, special events, restricted areas), who is the designated personnel, and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept (must be at least one month). e) Alarm systems, closed-circuit television, video surveillance, and security technologies must have an alternative energy source that allows them to continue functioning in case of an unexpected loss of direct power. Therefore, indicate if the alarm and closed-circuit television/video surveillance system and security technologies are backed up by an electrical power plant that guarantees their functioning. These systems should have an alarm/notification function that indicates a failure condition in operation and/or recording, indicate if their systems have such a function. f) Indicate if, in addition to alarm systems, closed-circuit television, video surveillance, they use any other type of technology to strengthen the security measures already in place. g) Describe the procedure implemented to regularly test and inspect alarm systems, closed-circuit television, video surveillance, and security technologies and ensure their proper functioning. The results of inspections and functional tests must be documented, as well as necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. h) Indicate if the alarm and closed-circuit television/video surveillance system provider has access to security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for such monitoring.
3.1 Security personnel. The railway transport concessionaire company must have security and surveillance personnel. This personnel plays an important role in the physical protection of the facilities, yards, and/or the place where traction and towing equipment are stored (boxcars, gondolas, hoppers, tank cars, containers, chassis, trailers, platforms that do not have their own traction that circulate on railway tracks and are used to transport merchandise inside them and in containers, as well as to control the access of all people to the property). Security personnel must have a documented procedure to carry out their functions, and have full knowledge of mechanisms and procedures in emergency situations, detection of unauthorized persons, or any incident in the facilities. Management must periodically verify compliance with procedures, policies, and functions through internal audits with the objective of verifying their correct execution.
Response: Explanatory Notes: Describe the documented procedure for the operation of security personnel, and ensure not to exclude the following points: a) Indicate the number of security personnel working in the company. b) Point out the positions and/or functions of the personnel, and operating hours. c) In case of hiring an external service, specify the number of personnel employed, operational details, records, reports, etc. d) In case of having armed personnel, describe the procedure for the control and safeguarding of weapons.
3.2 Identification of employees, visitors, and suppliers. There must be an identification system for employees, visitors, and suppliers for access to the facilities. Employees should only have access to those areas they need to perform their functions. Visitors and suppliers must present official photo identification upon arrival and a record must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by company personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provided provisional identification in a visible place. This procedure must be documented. The management or security personnel of the railway transport concessionaire company must properly control the issuance and return of identification badges for employees, visitors, and suppliers and ensure that they always wear the provided identification in a visible place. This procedure must be documented, as well as procedures for the issuance, return, and change of access devices (for example, keys, proximity cards, etc.). Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Attach the documented procedure for the control of identifications. Describe the procedure for the identification of employees, and ensure not to exclude the following points: a) Identification mechanisms (Photo ID badge, uniform, etc.). b) Indicate whether employees use uniforms, how they are assigned (by position, area, functions, etc.) and withdrawn (if applicable). c) Indicate how personnel hired by a business partner, working within the facilities (contractors, subcontractors, etc.) are identified. The procedure must also describe how the company issues, changes, and withdraws employee identifications and access controls, and ensure to include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Describe the procedure for the access control of visitors and suppliers, ensuring to include the following points: a) Point out what records are kept (personal forms for each visit, logbooks). b) The record of visitors and suppliers must include the following:
3.3 Procedure for identification and removal of unauthorized persons or vehicles. The railway transport concessionaire company must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles.
Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: a) Responsible personnel. b) Designate a person or area responsible for being informed of incidents. c) Instructions for confronting and approaching unidentified personnel. d) Point out in which cases the corresponding authorities must be notified. e) How the recording of incidents and measures adopted in each case is carried out.
3.4 Courier and package deliveries. Courier and package deliveries intended for personnel of the railway transport concessionaire company must be examined upon arrival and before being distributed to the corresponding area. Likewise, the company must have a documented procedure for the receipt and review of courier and packages, which must be communicated to the responsible personnel through training. The training must be documented.
Response: Explanatory Notes: Describe the procedure for the receipt and review of courier and packages, and ensure not to exclude the following: a) Personnel in charge of carrying out the procedure. b) Indicate how the personnel or provider of the courier and package service is identified (point out if an additional procedure to the supplier access procedure is required). c) Point out how packages are reviewed and/or what mechanism is used, as well as the records kept and, if applicable, incidents detected. d) Point out what action is taken in the case of detecting a suspicious package. e) Indicate how the inspection recording is carried out and, if applicable, of detected incidents.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, or renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to detect clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of such partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, if applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection of new commercial partners and monitoring of partners already working with them (this comprises any type of supplier that has a commercial relationship with the company, which is in the following sub-standard where it is requested to differentiate those at risk in their supply chain) and ensure to include the following points: a) What information is required from your commercial partner. b) What aspects are reviewed and investigated. c) Indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others), recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a commercial partner is not reliable and thus, carry out a deeper investigation and evaluate if one should work with them.
d) Indicate if you maintain a file for each of your commercial partners, as well as the information it must contain. e) Point out how the services of your commercial partner are evaluated and what points you review. The file must include at least the following: a) Company data (name, RFC, activity, etc.). b) Legal representative data. c) Proof of address. d) Commercial references (if applicable). e) Contracts, agreements, and/or confidentiality agreements and security policies. f) Security policies. g) If applicable, certificate or certification number in the security programs to which they belong.
4.2 Security requirements. The railway transport concessionaire company must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in its supply chain such as, companies providing terminal operation services, parts and/or spare parts suppliers, mechanical or any other service suppliers, customs brokers, land transporters, private security, companies providing transport medium repair services, cargo and merchandise loading/unloading service providers, as well as those resulting from the analysis carried out. The requirements must be based on the criteria and objectives of this Profile, or in case of existence, the specific Profile for each actor of the supply chain that corresponds to them. The railway transport concessionaire company must request from its commercial partners the documentation that accredits and proves that they comply with the minimum security standards established in this Railway Transport Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses backed by documentation that supports compliance with the requirements established by another Authorized Economic Operator Program. Likewise, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of the company's commercial partners that provide their services within the facilities, they must be obliged to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure indicating how you carry out the identification of commercial partners that require compliance with minimum standards in terms of security and how these comply with such requirements. Ensure to include the following points: a) Indicate a register of commercial partners that must comply with security requirements, and mention what type of providers these are (Transporters, Warehouses, Custody Service, Security Company, Transport Medium Repair Service, Loading and Unloading Service, Customs Brokers, etc.).
b) Indicate in what documentary manner (conventions, agreements, contractual clauses and/or addenda) you ensure that your commercial partners comply with security requirements. c) Indicate whether there are conventions, contractual agreements, contractual clauses and/or addenda regarding the implementation of security measures with your service providers within your company, such as: security, private security, cafeteria, gardening, cleaning and maintenance services, Information Technology providers, etc. d) Indicate whether you have commercial partners to whom it is required to belong to a supply chain security program, (for example: C-TPAT or any other World Customs Organization Authorized Economic Operator Program), as well as the information and documentation requested of them.
4.3 Commercial partner reviews. The railway transport concessionaire, through the Security Committee, must carry out periodic security evaluations (as well as those derived from risk situations) of the processes and facilities of business associates based on a risk analysis to guarantee that they meet the minimum security standards required by the company based on the Authorized Economic Operator Program. Maintain records of these evaluations, which allow verifying that the processes and security measures are being executed, as well as the corresponding follow-up.
When inconsistencies are found, the railway carrier must communicate them to their partner and/or supplier and provide a justified period to address the observations or areas for improvement identified, or otherwise, take the necessary measures to sanction them.
Conducting security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program. Therefore, in addition to a documented procedure, there must be a program or schedule for the execution of these security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company is unaware of whether the processes and facilities of its commercial partners are functioning correctly, it puts its supply chain at risk.
Response: Explanatory Notes: Describe the procedure for carrying out evaluations to verify the security requirements (processes and facilities) of your commercial partners. Ensure you do not exclude the following points: a) The frequency with which you visit the commercial partner (these must be at least once a year and derived from risk situations). b) Program or schedule for the execution of security reviews. c) Record or report of the verification and, if applicable, the corresponding follow-up. d) The verification formats must be duly completed, including the date, name, and position of those participating in the review, signatures, etc.
e) Indicate what action measures are taken if commercial partners do not comply with the established security requirements. f) In the event of having commercial partners with C-TPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed, how you record it, and the actions you take if it is detected that it is suspended and/or cancelled, in accordance with what is established in your procedure.
The procedure must include: a) Frequency of visits; b) Security review points; c) Preparation of reports; d) Feedback and agreements with the commercial partner; e) Follow-up on agreements; f) Measures in case of detecting non-compliance with requirements; g) Record of evaluations; h) Area or person responsible for carrying out this procedure.
These control measures and procedures must be documented and ensure the integrity of import and export shipments from the point of origin to their final destination.
Likewise, there must be established procedures to prevent, detect, or dissuade undeclared materials or unauthorized personnel from accessing traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside and in containers). These control measures and procedures must be documented with the intention and objective of maintaining at all times the integrity of the means of transport and import and export shipments from the point of origin to their final destination.
5.1 Process Mapping. There must be a process map that describes step by step the operational flow for the transfer of railroad cars with foreign trade merchandise throughout the supply chain, including, but not limited to: customer request, crew assignment, if applicable, entry into the facilities of the customer, supplier, or seller (spur) that describes the delivery and withdrawal of railroad cars, the transfer to terminals, the car classification process, routes, sidings, or layovers.
Likewise, the railway carrier must have written procedures for the designation of the crew (Line Engineers, Train Drivers, Line Switchmen, Yard Engineers, Yard Masters, Yard Switchmen, Track Inspectors), train dispatchers, previously designed routes, collection or delivery of loaded railroad cars, and exchange of railroad cars with foreign trade merchandise with the connecting railway; handling of railroad car documentation; communication during the train route between intermediate or final points, their relationship with other supply chain actors such as customs brokers, logistics operators, contracting clients, among others.
Response: Explanatory Notes: a) Attach the documented procedure where you describe in detail the operational flow of your general transport service and the type of service you provide, which includes the designation of the crew, rolling stock/units, routes, collection and delivery of loaded railroad cars, handling of documentation, communication during the operation with other actors in the supply chain including your contractors. This process must include at least the following: b) Service request. c) Assignment of traction equipment (locomotives). d) Crew assignment. e) Service confirmation to the crew. f) Instructions to the crew. g) Collection of loaded railroad cars:
For the purposes of the administrative management and billing process, the railway transport concessionaire must have a documented procedure to receive and register the service request that the user will require, which must contain, at least, the following: a) Service Request, which includes, but is not limited to, at least the following information:
5.2 Delivery and receipt of railroad cars. The railway transport concessionaire must inform the crew (personnel) of the criteria and conditions that their clients demand for the handling of their cargo, as well as comply with the company's security guidelines for entering their facilities at the time of collection and/or delivery of railroad cars with foreign trade cargo.
The crew (personnel) must know the documents that will be delivered to them, which cover the ownership of the loaded cars to be transported. Likewise, with the documentation delivered to them, they must verify the number of the assigned trailing equipment (wagons or containers).
When cargo is stored overnight or for a prolonged period in railway terminals, measures must be taken to secure the cargo against unauthorized access; this area must be monitored by its alarm systems, closed-circuit television, and video surveillance, and have restricted access. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to ensure that these areas remain free of visible pest contamination.
Response: Explanatory Notes: Attach the documented procedure indicating the procedure for the delivery and receipt of cargo, and ensure it includes the following points: a) How you verify and guarantee that the cargo preparation areas and the immediate surrounding areas remain free of visible pest contamination. In the event of identifying any type of visible pest, contamination, trash, insects, grass, weeds, or tall grass, how you report it and what actions you take regarding it. In the event of identifying any type of visible pest, contamination, trash, insects, grass, weeds, or tall grass, how you report it and what actions you take regarding it. b) Indicate how you control or what security measures you have implemented to mitigate the risk of collusion or complicity among employees. Describe in detail the procedure for the assembly and disassembly of trains, as well as coupling and uncoupling of railroad cars in yards or terminals on classification tracks, clients (transfer terminals, automotive terminals, etc.), and at customs when the automated selection mechanism determines customs recognition.
5.3 Merchandise tracking procedure. The railway transport concessionaire is responsible for monitoring and supervising the integrity of traction and trailing equipment, as well as the merchandise inside the railroad cars from the moment of loading until its delivery at the established destination. Therefore, it must have documented procedures that establish the use of technology for the transfer of foreign trade merchandise. There must be a device capable of tracking the position of the railroad cars in which the merchandise is transported via GPS/Satellite Link during the time the transfer lasts, having continuous geographic coverage during the route.
The company must establish documented procedures to ensure at all times the location of the trains. These procedures must be carried out under a risk analysis that includes, but is not limited to, the identification of predetermined routes, estimated delivery times, between intermediate points, as well as overnight stays and/or rest (classification yards, exit customs, railway spurs, fuel loading, routine mechanical inspections, sidings or layovers, among others). Likewise, the measures and actions to be taken in the event of identifying any delay in the route due to weather conditions, mechanical incident, inspection by any authority, or any security incident must be included. There must be trained and authorized personnel to perform the monitoring and/or permanent traceability of trains that transport railroad cars with foreign trade merchandise.
The supervision and registration data of all trains in transit with railroad cars transporting foreign trade merchandise must be preserved for one month in case the authority and/or the railway carrier must carry out an evaluation due to a security incident. If, as a result of monitoring and follow-up, a real (or confirmed) threat to the security of a shipment is identified, the company must alert (as soon as possible) the commercial partners in the supply chain that may be affected and, if applicable, the authority as appropriate.
Response: Explanatory Notes: Detail if a review of predetermined routes is carried out based on your risk analysis and how it is documented. Likewise, train monitoring must be documented, and this record must contain the following information: a) Name of the crew. b) Origin and destination of the service. c) Clients. d) Type of cargo. e) Unit location records. f) Crew service log. Attach the documented procedure to perform the monitoring of trains with railroad cars transporting foreign trade merchandise. The procedure must include, but is not limited to, the following: The area and person(s) responsible in the company for tracking and monitoring the trains. a) Indicate who are the people authorized to monitor and/or track the trains and how they have been instructed and trained to perform this task. b) Indicate what form and/or systems you use to perform train monitoring. c) Frequency to review the status of the trains and according to your risk analysis, indicate the means of communication that exist with the crew (indicate if there is more than one way to communicate: cell phone, tracking system, global positioning systems (GPS), fixed supervision points, etc.). d) Indicate the frequency with which clients are informed of the location of the railroad cars containing their shipments, or if they share any tracking system. e) Indicate if there are documented procedures to act or report in case of a delay in the route (stops, mechanical failures, accidents, etc.). Indicate if the crew is trained to attend to mechanical failures of traction and trailing equipment. f) The procedure must also include that, in the event of identifying a real or concrete threat to the security of a shipment or means of transport; how the company informs the commercial partners of its supply chain that may be affected and, if applicable, the authority as appropriate, about this type of incidents or presumptions.
5.4 Processing of train car information and documentation. The railway transport concessionaire must have written procedures to ensure that both electronic and/or documentary information sent by its customers starting from their service request, during the movement and dispatch of the transfer of railroad cars containing their merchandise, as well as the information received by business associates, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information.
Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use.
Response: Explanatory Notes: Attach the documented procedure for the processing of information and documentation of railroad cars. Briefly explain what it consists of. a) Detail how you receive and transmit relevant information and documentation for the transfer of railroad cars with foreign trade merchandise with your commercial partners (indicate if you use a specific computer control system and briefly explain its function). Likewise, detail how you validate that the provided information is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. b) Indicate how business associates transmit information with the company and how they ensure its protection.
6.1 Customs Obligations. The railway transport concessionaire must have a documented procedure with the objective of complying with what is established in rule 1.9.11, transmitting electronically to the entry or exit customs office, or in case of transit, the clearance customs office, the exchange list within the times established in the General Rules of Foreign Trade (RGCE) before the arrival of the railway. This list must contain, in addition to the requirements provided in rule 4.2.14, the key and number of the customs declaration covering the merchandise, as well as the description thereof, in accordance with what is stated in the declaration, in the COVE or bill of lading respectively, as the case may be.
They must have a documented procedure with the objective of complying with rule 2.4.13, for the purposes of articles 20, fraction III, and 53 of the Law.
Regarding internal transits, they must have a documented procedure that clearly, precisely, and accurately contemplates notices to customs authorities caused by late arrival, likewise, for cases of destruction of merchandise. For the purposes of what is stipulated in article 128 of the Law and rule 4.6.17., these procedures must contemplate the deadlines established in Annex 15.
There must be a documented procedure in cases of temporary import, return, and transfer of railroad cars by the railway company in accordance with what is stated in rule 4.2.14, as well as, regarding the temporary export of national or naturalized locomotives carried out by railway transport concessionaires, they must comply with the terms of articles 115 and 116 of the Law, as stated in rule 4.4.3.
They must have a documented procedure for cases where railroad cars suffer damage and must be destroyed or changed to definitive import regime in accordance with articles 94 and 106, fraction V, subsections a) and e) of the Law, in accordance with rule 4.2.18.
Answer: Explanatory Notes: Attach the procedure for the electronic transmission of data with the customs authority. Attach the procedure to be followed when any railway equipment suffers damage. Describe the procedure to comply with customs in cases of temporary exports and imports of locomotives. Describe the procedure to be followed in the case of merchandise transit. Describe the procedure to comply with customs in cases of temporary import, return, and transfer of railway cars of the railway company.
7.1 Use of seals and/or locks on traction and trailing equipment. The use and placement of seals or locks on traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers) is considered a critical and necessary process to maintain the integrity of shipments transporting foreign trade merchandise. Therefore, the railway transport concessionaire must document procedures that include the control, safeguarding, assignment, and replacement of high-security locks and seals that meet or exceed ISO 17712. To this end, the railway company must have documented procedures for placing and verifying the correct application of seals, their inspection at intermediate points, final destination, and their replacement when opened by any authority.
In the event of such an inspection, drivers must notify and record any unusual anomaly or structural modification found in containers, wagons, etc., resulting from said review. The procedures must include the steps to follow if a seal is found to be altered, manipulated, or if there is an incorrect seal number in the documentation, the communication protocols with commercial partners involved in the supply chain, and the investigation of the security incident. These must be reported to security personnel, commercial partners who may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program.
The railway carrier must verify and evidence that, during loading points, as well as in reviews by any authority or due to changes in the original conditions of the shipment, high-security seals or locks are correctly applied and placed. In the case of consolidated cargo pickup and delivery operations that do not use consolidation centers to sort or consolidate cargo before reaching the destination, the transport company must, at each stop and before reaching the destination, place high-security seals on the traction and trailing equipment. The company's management or a security supervisor must perform periodic and documented audits of the high-security seals and/or locks; these reviews must include the verification of the inventory of stored seals and/or locks and the reconciliation with inventory records and shipping documents. Also, supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and Instruments of International Traffic to corroborate that the information is correct.
Likewise, in said procedure, it is necessary for the railway carrier to include matters related to the administration of high-security seals, which must include, the control, assignment, safeguarding, handling of discrepancies, and destruction of seals and locks. Regarding the provider of the seals and/or locks, it must be demonstrated how these comply with ISO 17712. It must also have documented procedures that clearly describe how high-security seals will be controlled by the railway company during route transit, and by way of example but not limitation, contain the following: a) Verify the correct placement of seals or locks according to the VVTT inspection method to evidence and rule out improper manipulations:
Answer: Explanatory Notes: Attach the documented procedure for the placement and review of seals and/or locks on traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers). This must include, among other aspects according to its operation: a) Verify that the seal or lock is intact and determine if there is evidence of improper manipulation. b) Use the VVTT inspection method. c) Review and cross-check the documentation containing the number of the original seal or lock and, in case, of the additional ones carried during the transport of the merchandise. In case of using a replacement seal and/or lock, said number must be registered within the company's control. If altered seals and/or locks are identified, they must be kept to help carry out the investigation of said incident or discrepancy. d) Review that closing devices, hinges, and pins are attached to the trailer or container by welding or with a rivet. Also, protective plates can be placed on the door hinges and/or a seal/adhesive tape placed on at least one side. Also, the correct functioning of handles, latches, and all other locking or closing mechanisms of the cargo vehicles must be verified to detect manipulations and any inconsistency before placing any sealing device. e) Indicate how they assign and replace high-security locks, in case that, during the route, it is inspected by another authority. If a seal and/or lock breaks in transit, the cargo must be examined, the number of the replacement seal and/or lock must be registered, and the driver must notify immediately when this happens, indicate who broke it and provide the new seal number. Attach the documented procedure for the control and handling of seals and/or locks. This must include, among other aspects according to its operation: a) What type of seals and/or locks are used in its operations (foreign trade, transit, storage, etc.). b) Who has access and how locks and/or seals are safeguarded. The management of seals and/or locks must be restricted only to authorized personnel; stored in a safe place, have an inventory, control of their distribution and tracking (record of seals used, as well as of the receipt of new seals and/or locks). c) Describe how the company's management or security supervisor participates in audits of high-security seals and/or locks, the reviews they perform, the records they generate, and the actions they take in case of identifying discrepancies. Also, how supervisors of the shipping area and/or warehouse managers verify seal numbers used in the means of transport and Instruments of International Traffic to corroborate that the information is correct (this process can also be included within the internal audits referred to in sub-standard 1.3 of this document). d) How discrepancies in seal and/or lock numbers are addressed. e) Indicate who the supplier(s) are and how they prove that the specifications of the seals and/or locks comply with ISO 17712 (attach certificate issued by the certifying company responsible for verifying compliance with the corresponding ISO). All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of traction and trailing equipment. The railway transport concessionaire must have procedures to permanently review traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers) used as Instruments of International Traffic, with the purpose of identifying natural or hidden compartments, using a checklist or format that includes the main points to review. Such review must be carried out by operators or personnel designated by the company for such effect. Likewise, the physical-mechanical conditions of the means of transport must be periodically reviewed to verify their proper functioning, and if applicable, that they meet or exceed the safety standards of NOM-064-SCT2-2001.
Inspections of traction and trailing equipment must be systematic, and carried out at the entry and exit of operational yards or storage sites; and in case, at the merchandise loading point (contracting company); and if the infrastructure allows, before arriving at the dispatch customs using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and monitored by alarm systems, closed-circuit television, and video surveillance. The documented procedure for its inspection must include, by way of example but not limitation, the following review points: Traction Equipment (locomotive and cab)
Likewise, before loading traction and trailing equipment used as Instruments of International Traffic, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide smuggling or that they have been contaminated with visible agricultural pests, keep a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of merchandise subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination. The driver must ensure before crossing that the locomotive and cab are clean and free of trash.
Answer: Explanatory Notes: Attach the documented procedure to carry out the security and agricultural inspection of the equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers). This must include, among other aspects according to its operation: a) Those responsible for carrying out the inspection. b) Formats used to carry out the inspection that comply with the minimum requirements indicated in this sub-standard; likewise, in the case of transport companies of hazardous materials and waste, each equipment must have a daily visual review log of the traction and trailing units. Description of the place or places where the inspection is carried out and indicate how it is monitored by alarm systems, closed-circuit television, and video surveillance. a) The review points for means of transport, trailers, semi-trailers, and containers both for security and those for quality and agricultural inspections with the purpose of looking for visible pests. b) Instructions for the driver to ensure before crossing that the locomotive and cab are clean and free of trash. Attach the established format for the inspection of traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers). Likewise, the security and agricultural inspection format must include the following information: a) Date of inspection; b) Time of inspection; c) Vehicle plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected, and f) Name of the employee performing the inspection and the supervisor. The security and agricultural inspection formats may be signed by the supervisor to corroborate their information and be part of the import and export documentation. The documentation must be kept for one year for an investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements. Likewise, describe the procedure carried out on traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers) that contemplates the physical-mechanical conditions for safe operation on railway infrastructure within the country. In addition to validating that they have records of this type of maintenance for at least one year.
Said procedure must additionally include the following: a) Responsible personnel. b) Places where inspections are carried out. c) In case any physical-mechanical condition and/or anomaly is detected that affects the proper functioning of the traction and trailing equipment, how they are reported, and what measures must be taken. d) Indicate what type of record is kept. In cases where, due to major structural modifications in traction and trailing equipment such as axles, springs, structural modifications or body of the railway car, and even adaptations in the cabins, among others, the owner and responsible party of the railway car must contemplate, in accordance with its risk analysis, a more exhaustive review of the railway equipment in question to ensure its integrity, in this regard: a) Indicate if the repair or maintenance of traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers) is performed in the same facilities, or is carried out with an external provider. b) Briefly describe how the delivery-receipt of traction and trailing equipment that suffered a modification as commented in the previous paragraph is carried out.
7.3 Storage of traction and trailing equipment. The railway transport concessionaire must maintain the integrity at all times of traction and trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers) by establishing controls within its facilities. If these are empty and must be stored on tracks designated for this purpose, they must be secured with a lock and/or indicative seal, or in case, in a secure area that is guarded and/or monitored. When any traction or trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers) with foreign trade merchandise must be stored, it must be in a secure area with perimeter barriers and monitored by alarm systems, closed-circuit television, and video surveillance, to prevent unauthorized access and manipulation of the merchandise, so it must be, closed with a high-security lock according to ISO 17712. If during the route to the final destination, it is considered to move to a facility that is authorized as a storage yard for traction or trailing equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, platforms that do not have their own traction circulating on railway tracks and used to transport merchandise inside them and in containers), whether of its own or through a third party, the railway carrier must guarantee that said facilities meet the minimum criteria in terms of security based on the Railway Carrier Profile established by AGACE, or in case, of another Authorized Economic Operator Program.
Response: Explanatory Notes: Describe how you ensure the integrity of the traction and towed equipment that transport foreign trade merchandise (boxcars, gondolas, hoppers, tank cars, chassis, trailers, and platforms that do not have their own traction, which circulate on railway tracks and are used to transport merchandise inside them and in containers). Indicate the types of seals and/or locks used for the traction and towed equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, and platforms that do not have their own traction, which circulate on railway tracks and are used to transport merchandise inside them and in containers). Indicate how many tracks at the terminals or stations the railway company contemplates for the storage of traction and towed equipment (boxcars, gondolas, hoppers, tank cars, chassis, trailers, and platforms that do not have their own traction, which circulate on railway tracks and are used to transport merchandise inside them and in containers), and add the following data for each of these: a) Name or denomination of the track at the station or terminal. b) Location of the track at the station or terminal. c) Length of the storage track. d) Indicate how many freight cars with foreign trade merchandise enter the storage track (import/export). e) Number of people working at this station or terminal. f) In case any station or terminal has been visited by CTPAT, indicate the date on which the visit was carried out. g) Indicate in each of the facilities which one belongs to the concessionaire company or is a service contracted through a third party. h) Describe how you ensure that your commercial partner providing the storage service meets the minimum requirements in terms of security.
7.4 Security on railway tracks. The railway company must maintain the integrity of the railway tracks at all times, establishing review and conservation controls for both the concessioned railway tracks and the signage in yards, crossings, and streets. The use and placement of signage on railway tracks is considered a necessary process to maintain the integrity of freight cars transporting foreign trade merchandise; therefore, the company must document procedures that include the control, review, assignment, conservation, and replacement of signage that complies with or exceeds the Official Mexican Standard NOM-050-SCT2-2017, provision for the signage of level crossings of roads and streets with railway tracks, published in the DOF on July 11, 2017. The railway carrier must verify and evidence that during the review and conservation of railway tracks and signage, a logbook is maintained regarding the state of the railway tracks and signage.
Response: Explanatory Notes: Describe how you ensure the integrity and maintenance of the railway tracks. Indicate the types of signage used and how you comply with or exceed the Official Mexican Standard NOM-050-SCT2-2017, provision for the signage of level crossings of roads and streets with railway tracks, published in the DOF on July 11, 2017. Indicate the signage contemplated by the company within its concession.
8.1 Employment Background Verification. The railway transport concessionaire company must have documented procedures to investigate and verify the information stated in resumes, criminal records (if local legislation and company policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either independently or through an external company. Similarly, for positions that require it due to their sensitivity and affect the security of transport means, in accordance with the risk analysis previously conducted, stricter requirements for hiring must be considered, which must be carried out periodically (e.g., Train Dispatchers, Road Engineers, Train Drivers, Road Switchmen, Yard Engineers, Foreman, Yard Switchmen, Track Inspectors, operators/engineers). Regarding personnel already working in the company, periodic investigations must be conducted based on the activities and/or sensitivity of the employee's position. This procedure must contemplate the creation and updating of personnel files, which must have restricted access and contain the following information: a) Employment application. b) Updated photograph (in electronic or printed format). c) Copy of official identification. d) Copy of the valid Federal Railway License (Train Dispatchers, Road Engineers, Train Drivers, Road Switchmen, Yard Engineers, Foreman, Yard Switchmen, Track Inspectors, etc.) issued by the SICT according to the type of service to be provided. e) Copy of updated proof of address. f) Copy of birth certificate. g) Registration with Social Security Institutions. h) Recommendation letters. i) Evaluations (Toxicological Examination mandatory for Train Dispatchers, Road Engineers, Train Drivers, Road Switchmen, Yard Engineers, Foreman, Yard Switchmen, Track Inspectors, operators/engineers) at least every six months. j) Hiring terms. k) Minimum mechanical knowledge examination. Similarly, for sensitive positions identified in the previously conducted risk analysis and directly affecting the security of transport means, stricter requirements for hiring must be considered, which must be carried out periodically (e.g., Train Dispatchers, Road Engineers, Train Drivers, Road Switchmen, Yard Engineers, Foreman, Yard Switchmen, Track Inspectors, operators/engineers).
Response: Explanatory Notes: Describe the documented procedure for personnel hiring and ensure you include the following: a) Requirements and documentation demanded. b) Tests and examinations requested. Indicate the areas and/or critical positions identified as risky, according to your analysis, and indicate the following: a) Indicate what the additional requirements are for specific areas and/or jobs, such as criminal records (if legislation and company policies allow), non-criminal background letters, socioeconomic studies, clinical, toxicological (drug use) studies, etc. In your case, indicate the jobs or work areas where they are required and with what periodicity they are carried out. b) Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. c) Indicate the medical and toxicological examinations performed on train dispatchers, road engineers, train drivers, road switchmen, yard engineers, foremen, yard switchmen, track inspectors, operators/engineers. d) In case of hiring a service agency for personnel hiring, indicate if it has documented procedures for personnel hiring and how you ensure they comply with the same. Briefly explain what they consist of. The procedures for personnel and contractor hiring may include: a) Thorough investigations of the work and personal backgrounds of new employees. b) Confidentiality and responsibility clauses in employee contracts. c) Specific requirements for critical positions. d) In your case, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. The company may consider the results of candidate background verifications, as allowed by current legislation, to make hiring decisions. Background verifications are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel Termination Procedure. Documented procedures must exist for personnel termination, which include the delivery of identification and any other items provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include the termination in those systems, both computer access systems, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel termination, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the delivery of identification, uniforms, keys, and other equipment is carried out and confirmed. c) Indicate the control, record, and/or format in which the delivery of material and termination in computer systems (if applicable) are identified and ensured (attach if applicable). d) Indicate the type of records of personnel who ended their labor relationship with the railway company, so that in case it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel Administration. The railway transport concessionaire company must maintain an updated system, control, or database of active employees. Likewise, affiliation records with social security institutions and other legal labor records must be created and kept updated. In case the company has personnel contracted by its commercial partners working within the facilities, it must ensure that they meet the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate if the company has an updated system, control, or database, both for directly hired personnel and that hired through a service provider company, and ensure it includes, among others, the following points: a) Full name. b) Updated photograph at least every five years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). d) Family ties. e) Work background. f) Diseases. g) Medical examinations. h) Training. i) Type of license and its status (they must have a record of federal railway licenses with the corresponding validity, in order to prevent their Train Dispatchers, Road Engineers, Train Drivers, Road Switchmen, Yard Engineers, Foremen, Yard Switchmen, Track Inspectors, engineers, and operators from traveling with expired licenses). j) Results of periodic evaluations. k) Observations. l) This personnel must be hired in accordance with current labor laws and regulations.
9.1 Document Classification and Handling. Procedures must exist to classify documents according to their sensitivity and/or importance, with special emphasis on that received from their contractors where information related to routes, materials, merchandise, and/or goods being transported, instruction letters, schedules, customer and/or contact names, among others, is described. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. Reviews must be conducted regularly to ensure that documents are not used improperly. The useful life of the documentation must be identified, and procedures for its destruction must be established. The railway company must conduct regular reviews to verify access to information and ensure that it is not used improperly. Reports, books, cargo guides, work orders, train consist, track listings, statistics, and any other document related to railway transport activity. The foregoing, in accordance with what is stipulated in the Regulatory Law of the Railway Service, the Federal Self-Transport and Auxiliary Services Regulation, and the Regulation for the Land Transport of Hazardous Materials and Waste.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: a) Control register for delivery, loan, among others, of documentation. b) Restricted access to the archive area. c) Storage and classification policies. d) An updated security plan describing the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. e) In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards that must be communicated through a training program for all employees handling computer equipment and systems, which includes topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow their employees to connect remotely to a network must employ secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when outside the office, as well as procedures designed to prevent unauthorized remote user access. For the above, written procedures and infrastructure must exist to protect the company against losses, theft, leakage, hacking, and/or ransomware of information; this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology systems and detect inappropriate access and/or improper manipulation or alteration of business and commercial data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, including phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access. If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery or replacement of Information Technology systems and/or data, which includes how you back up and ensure the security of your information, in addition to protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which information backups are carried out. b) Who has access to them and who authorizes the recovery of information. c) Indicate what type of tests you perform and how often, to verify the security of the network, systems, and infrastructure. d) Mention if, to carry out this type of tests or vulnerability scans, you do so through software, a third party, or provider, and if so, indicate the name or corporate name. e) In case vulnerabilities are found, describe the corrective actions that must be implemented. f) Indicate if you share information about cybersecurity threats with your commercial partners participating in your supply chain (for example: communications, bulletins, emails, etc.).
g) Systems must be protected by passwords and must be modified frequently; therefore, indicate the procedure for changing them. h) Indicate if there are information security policies for their protection. i) Have a system or software to detect and identify abuse, intrusion, or unauthorized access by persons to your systems, and/or Information Technology data (any system used by the railway company), as well as the abuse of policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology security systems and policies. Information technology and cybersecurity policies and procedures must be reviewed annually and updated due to an attack or according to situations that may put the company's systems at risk. Describe the security measures you use to allow your employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when outside the office. In case of allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to access the company network securely. Indicate if commercial partners have access to the company's computer systems. If so, indicate what programs and how they control access to them. Indicate if the computer equipment has a backup power supply system that allows business continuity.
The procedures regarding the company's information backup must also include: a) How and for how long data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in case of incident and how to recover information. c) Frequency and location of backup copies and archived information. d) If backup copies are stored in sites alternative to the facilities where the data processing center is located. Tests of the validity of data recovery from backup copies. The procedures regarding the protection of the company's information must also include: a) An updated and documented policy for the protection of the company's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. b) Detail if you operate with multiple systems (headquarters/sites) and how these systems are controlled. c) Who is responsible for the protection of the company's computer system (responsibility should not be limited to one person but to several so that each can control the actions of the rest). d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information must be limited to personnel authorized to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if necessary, report that access to confidential systems is based on job requirements. e) Indicate the elements or format that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or what area provides those passwords.
f) Indicate the name of the "firewall" and antivirus used, (include licensing information), demonstrating that this security software is active and receives periodic updates. For the above, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses (software and hardware). All computing equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be discarded, there must be a documented procedure that includes how they should be formatted, disinfected, or destroyed appropriately to avoid information leakage.
g) In the event of staff turnover, access to computing, telecommunications, and network equipment must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc.
h) Measures planned to handle incidents in case the system is compromised.
10.1 Training and awareness on threats. The railway transport concessionaire must have a training and awareness program on security policies in the supply chain directed to all its employees (operational and administrative), and additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it. Likewise, specific training must be offered according to their functions to help employees maintain the integrity of traction and towing equipment for agricultural and security purposes, incident management, receipt and review of messaging and packages, prevention of operations with proceeds of illicit origin (money laundering, terrorist financing, etc.), how to recognize and report internal conspiracies, protect access controls, as well as training regarding smuggling, theft of goods, placement of high-security seals and locks (VVTT inspection method), prevention of visible contamination by pests, etc. These topics must be established as part of new employee onboarding and periodically maintain update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the company's procedures.
In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train staff on the company's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or information kidnapping), including access to computing equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodically maintain update programs. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the company, and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. The foregoing, in accordance with the regulation established by SICT, which establishes that permit holders have the obligation to provide their operators with training and coaching to achieve efficient, safe, and effective service provision.
Response: Explanatory Notes: Must have a training program on security and prevention of security incidents in the supply chain for all employees working for the concessionaire company (administrative, operational, direct or indirect). Briefly explain what the training program consists of and ensure to include the following: a) Brief description of the topics taught (onboarding, specific periods, derived from audits, security incidents, etc.). b) When they are taught (onboarding, specific periods, derived from audits, security incidents, etc.). c) Frequency of trainings, as well as updates and reinforcement. d) Indicate how participation in supply chain security trainings is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of attendees, the topics taught, in addition to having measures to verify that the training provided met all objectives of the same. e) Explain how employee participation in supply chain security issues is encouraged.
Training to perform reviews of traction and towing equipment for agricultural and security purposes must include the following topics: a) Signs of hidden compartments. b) Smuggling hidden in natural compartments. c) Signs of pest contamination. d) Procedures to follow if something is found during an inspection of the transport medium or if a security incident occurs during transit. e) Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials, in accordance with the International Standard for Phytosanitary Measures called Regulation of wooden packaging used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations, and the identification of infested wood. Operators and personnel who perform agricultural and security inspections of traction and towing equipment must be trained to inspect cargo vehicles for such purposes. Indicate if you have a training program on security in the supply chain, focused on operators/machinists. Briefly explain what it consists of. a) Indicate how participation in supply chain security trainings is documented. b) Explain how employee participation in security issues is encouraged. c) Indicate how you keep records of participants in trainings. Frequency of trainings and, if applicable, updates. The topics that may include, by way of example and not limitation: a) Access and security policies at facilities. b) Handover-receipt of railroad cars. c) Confidentiality of cargo information. d) Transfer instructions, train documents, work orders. e) Accident and emergency reports. f) Instructions for placing locks and/or seals in case of inspection by other authorities. g) Installation and testing of security alarms and unit tracking, where applicable. Identification of authorized formats and documents to be used.
11.1 Reporting of anomalies and/or suspicious activities. In the event of detection of anomalies and/or suspicious activities, related to the security of the supply chain and in accordance with its logistical processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), these must be reported to security personnel, business partners that may be part of the affected supply chain, security specialist or Authorized Economic Operator Program contact, and other competent authorities, keeping a record of said anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to report or denounce anomalies and/or suspicious activities, as well as those containing mechanisms to anonymously report problems related to security, and ensure to include the following: a) Who is responsible for reporting incidents. b) Detail how you determine and identify with which authority to communicate in different scenarios or presumption of suspicious activities. c) Mention if you keep a record of the reporting of these activities and/or suspicions and briefly describe what it consists of.
11.2 Investigation and analysis. There must be written procedures to denounce or report anomalies and/or suspicious activities, as well as for the analysis and investigation of security incidents in the supply chain to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented and available at all times for authorities that so require. This information and documentation generated to carry out the foreign trade operation of the affected goods that allows identifying each of the processes through which the transport medium passed, up to the point where the incidence was detected and that allows recognizing the vulnerability of the chain.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any security incident, and ensure to include the following: a) Person responsible for carrying out the investigation. b) Documentation that integrates the investigation file. The documents to be included in the file derived from the investigation, by way of example and not limitation, may be: a) Information related to the Train Dispatchers, Road Machinists, Train Drivers, Road Switchman, Yard Machinist, Foreman, Yard Switchman, Track Inspector, personnel in charge, railroad cars with cargo, and routes. b) General information of the shipment, Purchase Order. c) Transport request; Confirmation of transport medium; Identification of the transport operator (Access records, etc.). d) Container Inspection Formats; Exit order; delivery records. e) Videos from alarm systems, closed-circuit television, and video surveillance. f) Documentation generated for the railway carrier (packing list, bill of lading, BL, instruction sheet). g) Documentation generated for business partners (Description of goods, Proformas, invoices, etc.). h) Documentation generated by the business partner (Customs declarations, Manifests, Tracking and inspection reports, videos if applicable, etc.). i) Tracking and monitoring report of the unit (GPS Tracking).
E10. Industrial Parks Profile. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data provided will replace the data provided when you requested your authorization. General Information The objective of this Profile is to ensure that the industrial park develops and implements security practices and processes that ensure its supply chain by mitigating the risk of contamination of its facilities. Industrial parks interested in obtaining the authorization referred to in rule 7.1.5. must have documented and verifiable processes. Likewise, the industrial entity interested in the aforementioned authorization must integrate the criteria required in this document into the model or business design it has established, seeking during the implementation of security standards the application of an analysis culture that supports decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the company itself. During the filling out of this document, those interested in obtaining certification will analyze and identify threats that allow them to implement practices and security processes that ensure their supply chain and minimize the risk of contamination or counterfeiting with illicit goods of the companies they house.
Filling Instructions:
You must fill out an Industrial Parks Profile for each industrial park where companies carrying out foreign trade operations are housed.
Describe in detail how the industrial park complies with or exceeds what is established in each of the subsections as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Description of the standard. 1.1 Sub-standard Description of the sub-standard Response Explanatory Notes Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards, for which you must attach the procedures in Spanish; these procedures must be characterized by describing or defining the objective the document pursues, the start and end of the process, measurement indicators, requirements, documents or formats to be used, responsible parties, among others. The section regarding Explanatory Notes is a guide regarding the points that must be included in the Response of each sub-standard, indicating those points that should not be excluded from your response.
Once this Industrial Parks Profile is answered, you must attach it to the Application for inscription in the Certified Trading Partner registry referred to in the first paragraph of rule 7.1.5., fraction IV, subsection a).
For the purpose of verifying what is stated in the previous paragraph, the SAT through the AGACE may carry out an inspection at the installation indicated here, with the exclusive purpose of verifying what is stated in this document.
Any incomplete Industrial Parks Profile will not be processed.
Any question relative to the Application for inscription in the registry of certified companies and to the Industrial Parks Profile, direct it to the contacts appearing on the SAT Portal.
In the event of being authorized as a Certified Trading Partner, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and derived from these changes or modifications in the information stated and provided in this Industrial Parks Profile to the authority are required, in accordance with what is established in rule 7.2.1., fourth paragraph, fractions I, II, and VII.
When derived from the inspection visit, non-compliance related to minimum security standards results, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the indicated non-compliances. Installation Data An Industrial Parks Profile must be filled out for each of the installations that belong to and operate under the same RFC and carry out manufacturing processes of products subject to foreign trade, and in their case, for those installations related as industrial and/or manufacturing plants, warehouses, distribution centers, consolidation, etc. Installation Information Profile Number of Industrial Parks: of RFC Name and/or Business Name: Name and/or Denomination of the Installation Type of Installation Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Age of the installation (years of operation) Predominant activity No. of total employees at this installation: Surface area of the installation (M2):
Certifications: (indicate if you hold certifications that you consider impact your supply chain process, for example: ISO 9000; Reliable Logistics Processes, among others) Name: Category: Validity: Name: Category: Validity: Name: Category: Validity: Name: Category: Validity:
1.1 Risk Analysis. Industrial parks must establish measures to identify, analyze, and mitigate security risks within their facilities, particularly in areas that are common or shared by the companies domiciled within them. For this reason, a written analysis must be developed to determine risks based on the organization's model (example: geographic location, crime index, predominant activity of co-owners and/or tenants, type of merchandise, hazardous, high value, etc.), which allows implementing and maintaining appropriate security measures. Based on the above, there must also be a written process based on the risk analysis to select new business partners and monitor those with whom the company is already working. This procedure must be updated at least once a year, so that it allows identifying other risks or threats in the Park's facilities, due to the result of a security incident or those originating from changes in the initial conditions of the operation, as well as to identify that the policies, procedures, and other control and security mechanisms are being complied with. It is important to note that the company's Security Committee must participate in the preparation and updating of the risk analysis and the maintenance of the Authorized Economic Operator Program.
Response: Explanatory Notes: Indicate what sources of information are used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the Industrial Park facilities, which must include at least the following points: a) Frequency with which the risk analysis is reviewed and/or updated. b) Areas and/or companies in the Industrial Park that are incorporated into the risk analysis. c) Methodology or techniques used to perform the risk analysis. d) Persons responsible for reviewing and/or updating the company's risk analysis.
Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the risk appreciation and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Identification of risks in its supply chains and its facilities. c) Risk analysis (causes, consequences, probabilities, and existing controls to determine the level of risk as high, medium, and low). d) Risk evaluation (decision-making to determine the risks to be treated and priority for implementing treatment). e) Risk treatment (application of alternatives to change the probability of risks occurring). f) Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use risk administration, management, and evaluation techniques in accordance with international standards ISO 31000, 31010, and ISO 28000, which, according to its business model, must be implemented.
1.2 Security Policies. Industrial parks must have a policy oriented towards preventing, securing, and recognizing threats in the supply chain and the company's facilities, such as drug trafficking, money laundering, arms trafficking, human trafficking, prohibited merchandise, and acts of terrorism. On their part, the co-owners and/or tenants operating in the industrial park must sign and comply with their security policy. The above, regardless of whether some companies do not carry out foreign trade operations or are already certified in supply chain security. To promote a culture of security, companies must demonstrate their commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. Senior officials or executives of the company who must endorse and sign the security policy may include the company president, chief executive officer, general manager, security director, or personnel with equivalent rank with decision-making authority.
Response: Explanatory Notes: State the security policy oriented towards preventing, securing, and recognizing threats in the supply chain and the company's facilities, indicate who is responsible for its review, signature, and dissemination to employees, as well as the frequency with which it is updated. This policy must be communicated to employees through a dissemination program and/or campaign. The security policy must be signed by a senior official of the company and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the company's initial and reinforcement training. There must be records of the security policy signed by co-owners and/or tenants operating in the park acknowledging and accepting it.
1.3 Internal Audits in the Supply Chain. In addition to routine monitoring and supervision of security controls, it is necessary to schedule and carry out periodic audits, which allow evaluating all processes regarding supply chain security in a more critical and in-depth manner, as well as ensuring that employees follow the company's security procedures. Audits must be carried out by the company's Security Committee, establishing a documented procedure, as well as a program or calendar for their execution. Although it is necessary that audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, the nature of risks, business model, and variations between facilities. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and ensure that employees follow the company's security procedures. The review process does not have to be complex; however, the formats and records used for the application of such reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. The senior management of the Industrial Park Corporate entity must review the audit results and undertake the required corrective or preventive actions. The audit process must ensure that the necessary information is collected to allow management to make this evaluation. The review must be documented, in addition to the fact that the company's Security Committee must provide and record periodic updates on the progress or results of any audit, exercise, or validation.
Response: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on supply chain security; ensure you include the following points: a) Indicate how the company carries out the scheduling or calendarization to perform an internal audit on security, in the supply chain, and facility security. b) Indicate who participates in them, and the records made thereof, as well as the frequency with which they are carried out. c) Indicate how the management of the Industrial Park Corporate entity verifies the results of security audits, how it carries out and/or implements preventive, corrective, and improvement actions, in addition to the follow-up and closure thereof. d) The formats used during internal audits must be properly filled out, and through them, evidence that security procedures and measures are being put into practice.
1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan; said plan must address crisis management, security recovery plans, and business resumption, to ensure business continuity in the event of a situation that affects the normal development of activities and foreign trade operations of the industrial park in its supply chain. A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, a bomb threat, the detection of suspicious packages, power outages, theft and/or damage to merchandise, (For example: roadblocks, internal roadway blockages, urban roadway blockages, shootings, threats, or extortions, entry of unauthorized personnel, damage to facilities, among others, customs closures). Such plans must be communicated to the industrial park personnel, as well as to the security managers of the companies established therein, through periodic training, as well as carrying out tests, practical exercises, and annual drills of the contingency and emergency plans to verify their effectiveness, from which there must be a properly filled-out and signed record (for example: result reports, minutes, or reports, which must be backed by video recordings, photographs, etc., demonstrating their execution). The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the organization's risk level.
Response: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in the event of an emergency or security situation that affects the normal development of foreign trade activities of companies installed in the industrial park. This procedure must include, by way of example and not limitation, the following: a) What situations it contemplates, describing the action plan and steps to be followed in case of crisis, as well as the tasks assigned to personnel during the handling of such contingencies. b) What mechanisms it uses to disseminate and ensure that these plans are effective. c) Contemplate the scheduling and carrying out of annual drills and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution).
2.1 Facilities. Facilities (administrative offices, industrial warehouses, storage, etc.) must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures, and in the event that an irregularity is detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, territorial limits, as well as various accesses, internal and external roadways, and the location of administrative buildings, industrial warehouses, storage areas, parking areas for employee and cargo vehicles, vacant lots, railroad spurs, and short- or medium-term expansion projects must be fully identified.
Response: Explanatory Notes: Indicate the predominant materials with which the facilities are constructed (for example, metal structure, sheet metal walls, brick walls, concrete, chain-link fence, among others), and indicate how the review and maintenance of structural integrity is carried out. Indicate the personnel or area responsible for carrying out inspection, maintenance, and damage repair tasks for the facilities. Attach a distribution or architectural plan of the complex, where limits, access routes, facilities, building locations, critical areas, parking, and boundaries can be identified. In the event that two owners or tenants of the Industrial Park carry out foreign trade operations and share a Warehouse or cargo vehicle maneuvering yard, this must be indicated in the overall architectural plan.
2.2 Gate and Booth Access. Entrance or exit doors for vehicles and/or personnel must be attended, controlled, watched, and/or supervised. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks.
Response: Explanatory Notes: Indicate how many doors and/or accesses (pedestrian, private cars, cargo vehicles, railroad spur) exist in the industrial park, as well as the operating hours of each, and indicate how they are monitored (Must have security personnel and indicate the number of elements). Detail if there are doors and/or accesses that are blocked or permanently closed. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls used).
2.3 Perimeter Fences. Perimeter fences must be installed to secure the perimeters of the industrial park, based on a risk analysis carried out by the corporate entity. Fences that prevent and deter intrusions into the industrial park must be used. These must be inspected regularly and carry a record of the review with the purpose of ensuring their integrity and identifying damage, which must be repaired as soon as possible by the personnel designated for these tasks.
Response: Explanatory Notes: Describe the type of fence, peripheral barrier, and/or walls with which the industrial park is equipped; ensure you include the following points: a) Specify what areas it encloses. b) Point out their characteristics (material, dimensions, etc.). c) In case of not having fences, justify the reason in detail and explain how this situation is remedied. d) Frequency with which the integrity of perimeter fences is verified and the records kept, with the purpose of ensuring their integrity and identifying damage, which must be repaired as soon as possible. e) Indicate the personnel or area responsible for carrying out inspection and damage repair tasks. f) Identify and point out restricted access areas. The procedure for inspecting perimeter fences could include: a) Personnel responsible for carrying out the review. b) How and how often fence and/or perimeter fence inspections are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that repairs and/or modifications meet the technical specifications and necessary security requirements.
2.4 Parking. Access to parking areas must be controlled and monitored by security personnel or personnel designated for this task; it must be prohibited for private vehicles (of employees, visitors, suppliers, and contractors, among others) to park outside assigned spaces, obstruct internal roadways of the park, access to control and inspection points, and, where applicable, to any other access point to the same.
Response: Explanatory Notes: Describe the procedure for controlling and monitoring parking areas; ensure you include the following points: a) Persons responsible for controlling and authorizing access to common area parking. b) Identify signage for common or shared parking (specify if parking assigned to park owners and tenants is separated from the cargo vehicle maneuvering yard). c) How entry and exit control of vehicles to the facilities is carried out (indicate the records made for controlling common or shared parking, existing control mechanisms (for example: badges, card readers, lanyards, etc.), how they are assigned, and the area responsible for doing so). d) Identify and point out common or shared parking.
2.5 Key and Lock Device Control. Windows, doors, booths, access gates, interior and exterior grilles, according to their risk analysis, must be secured with locking devices. All companies in the industrial park, without exception, must have a documented procedure for the handling and control of keys and/or locking devices for interior and exterior areas considered critical. Likewise, they must keep a record and establish signed liability letters by persons who have keys or authorized access according to their level of responsibility and tasks within their work area.
Response: Explanatory Notes: Indicate if all doors, windows, booths, access gates, windows, and interior and exterior grilles have manual or electronic opening and closing mechanisms. Attach the documented procedure for the handling and control of keys and/or locking devices; ensure it includes the following points: a) Persons responsible for administering and controlling key security. b) Format and/or control record for key lending. c) Treatment of loss or non-return of keys. d) Point out if there are areas where access is gained with electronic devices and/or some other access mechanism.
2.6 Lighting. The lighting of the interior and exterior perimeter of the industrial park must allow clear identification of people, material, and/or equipment located there, including the following areas: entrances and exits, perimeter fences, interior fences, loading and unloading, and parking areas, and must have an emergency and/or backup system in sensitive common-use areas.
Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system; ensure you include the following points: a) Point out which common or shared areas are illuminated and which have a backup system (indicate if it has an auxiliary power plant or some other mechanism to supply electricity in case of any contingency). b) How you ensure that the lighting system is appropriate in each of the areas where the companies in the industrial park are located, so that it allows clear identification of the personnel, material, and/or equipment located there. c) Person responsible for controlling and maintaining lighting systems. d) Maintenance and review program (if it coincides with another process, indicate it). e) Emergency protocol of the industrial park monitoring center in case of power outages, natural disasters, or sabotage. The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas requiring permanent lighting.
2.7 Communication devices. All companies in the industrial park without exception must have communication devices and/or systems to immediately contact their security personnel, the park's monitoring center, and the authorities in the event of an emergency or security situation. Additionally, a backup system must be available and its proper functioning verified periodically. Response: Explanatory Notes: Describe the procedure that personnel must follow to contact the security personnel of the industrial park's monitoring center or, in its case, the corresponding authority in the event of any security incident. Indicate whether the operational and administrative personnel of the companies in the park have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or the relevant party (these must be accessible to users to ensure a prompt response). Indicate what type of communication devices the security personnel of the industrial park use (landline phones, cell phones, radios, alarm system, etc.). Describe the procedure for the control and maintenance of communication devices; ensure you include the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate if backup communication devices are available in case the permanent system fails, and if so, briefly describe them. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Verification and maintenance records of the devices. c) Method of assignment of communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance systems. Alarm systems, closed-circuit television, video surveillance, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other considered sensitive areas, notify the corresponding area, and also be used as evidence in investigations derived from any security incident. The Industrial Park must have its own monitoring center or outsourced administration; likewise, these security systems and technologies must be placed according to a prior risk analysis, so that personnel, visitor, supplier, passenger vehicle, cargo access areas, and other considered sensitive areas remain monitored and watched. Such alarm and closed-circuit television and video surveillance systems must allow clear identification of the area or environment being monitored, record permanently, and maintain a backup of recordings for at least one month, in order to have the necessary elements to assign corresponding responsibilities in the event of a security incident. Alarm systems, closed-circuit television, video surveillance, and security technologies must have a documented operational procedure that includes supervision of the equipment's good condition and verification of the correct position of cameras, indicating the frequency with which backups of recordings must be made, as well as those responsible for their operation. This system and all security technology infrastructure must have restricted access. Response: Explanatory Notes: Mention the documented procedure indicating the functioning of the external central alarm system or sensors, and if applicable, describe the following points: a) Indicate if all doors and windows have alarm sensors, as well as the areas where motion sensors are available. b) Procedure to follow in case an alarm is activated. c) Indicate the personnel or area responsible for maintenance, how failures are reported, and the records they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances); ensure you include the following points: a) Indicate the number of security cameras installed in the alarm and closed-circuit television and video surveillance systems, and their location by area (detail if it covers the entry and exit points of the facilities, to cover the movement of vehicles and individuals). Attach a layout or map of the distribution of security cameras. b) Point out the location of the alarm and closed-circuit television and video surveillance systems and security technologies, where the monitors are located, who reviews them, as well as operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Periodic and random reviews of recordings must be carried out. Indicate how they are reviewed (randomly, weekly, special events, restricted areas, etc.), who the designated personnel are, and how management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept (must be at least one month). e) Alarm, closed-circuit television, and video surveillance systems and security technologies must have an alternative energy source that allows them to continue functioning in the event of an unexpected loss of direct power. Therefore, indicate if the alarm and closed-circuit television and video surveillance systems are backed up by a power generator or some other mechanism to supply electricity, guaranteeing their operation. These systems should have an alarm/notification function that indicates a failure in operation and/or recording; indicate if your systems have this function. f) Indicate if, in addition to the alarm, closed-circuit television, and video surveillance systems, any other type of technology is used to strengthen the security measures already in place. g) Describe the procedure implemented to regularly test and inspect alarm, closed-circuit television, and video surveillance systems and security technologies and ensure their proper functioning. The results of the inspections and functional tests must be documented, as well as any necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. h) Indicate if the provider of alarm, closed-circuit television, and video surveillance systems has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
Response: Explanatory Notes: Describe the procedure for employee identification and ensure you include the following points: a) Identification mechanisms (ID card and/or badge with photo, access control, biometrics, proximity cards, etc.). b) Indicate if employees use uniforms, how they are assigned (by position, area, functions, etc.) and removed (if applicable). c) Indicate how personnel hired by a business partner working within the facilities (security, cleaning, maintenance, contractors, etc.) are identified. The procedure must also describe how the industrial park delivers, changes, and withdraws employee identifications and access controls, and ensure you include the responsible areas for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). Attach the documented procedure for the control of identifications. 3.3 Visitor and Supplier Identification. To access the facilities, visitors, suppliers, and contractors must present official identification with a photo for documentation upon arrival and a record must be kept. All visitors, suppliers, and contractors must receive a temporary identification, be accompanied by company personnel during their stay in the facilities, and ensure that the visitor/supplier/contractor always wears the provisional identification provided in a visible place. This procedure must be documented. Regarding cargo vehicles entering the industrial park, there must be a control that allows verifying the means of transport, container, rail cars, trailers, and/or semi-trailers, in order to identify and mitigate the risk of contamination of the park with illicit products. Response: Explanatory Notes: Attach the procedure for the access control of visitors, suppliers, and contractors; ensure you include the following points: a) Point out what records are kept (personal forms for each visit, logbooks, among others). b) The record of visitors and suppliers must include the following:
Date of the visit.
Name of the visitor.
Identification number with photo (official documents such as: driver's license, passport, INE, etc.).
Entry and exit time.
In the case of vehicle access, the form must include the data of the private or cargo vehicle (model, license plate, trailer number, etc.). c) Point out who is the person responsible for accompanying the visitor and/or supplier and if there are restricted areas for their entry. d) Describe the type of control or security measures implemented regarding the entry of cargo vehicles (means of transport, containers, rail cars, trailers, and/or semi-trailers, etc.), in order to identify and mitigate the risk of contamination of the park with illicit products. 3.4 Procedure for identification and removal of unauthorized persons or vehicles. The Industrial Park's monitoring center must have a documented procedure specifying how to identify, confront, or report unauthorized or identified persons and/or vehicles; this procedure must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: a) Responsible personnel. b) Designate a person or area responsible for being informed of security incidents. c) Instructions for confronting and approaching unidentified personnel. d) Indicate in which cases the corresponding authorities must be notified. e) How security incidents are recorded and the measures adopted for each case. 3.5 Courier and package deliveries. Monitoring center personnel must identify the personnel of courier and package companies and authorize their entry to distribute and deliver correspondence addressed to companies located inside the industrial park. Response: Explanatory Notes: Attach the procedure to identify and authorize the entry of personnel from courier companies that distribute and deliver correspondence intended for companies installed in the industrial park, and ensure you include the following: a) How personnel or the courier and package service provider is identified (indicate if an additional procedure to supplier access is required).
Business partners. The Industrial Park's Corporate entity must have written and verifiable procedures for the selection of owners and tenants, as well as for the selection and contracting of new business partners and monitoring of partners already working with them, such as: cleaning service providers, private security, staffing, landscaping, contractors, installation and maintenance of alarm and closed-circuit television and video surveillance systems, Information Systems and Technology providers, among others, and according to their risk analysis, require them to comply with security measures to strengthen the international supply chain. The risk analysis that the Industrial Park's Corporate entity performs regarding its business partners (clients and suppliers) must include risks related to the identification of activities related to money laundering and terrorism financing. Additionally, the industrial park must foster a documented social compliance policy and program that, at a minimum, addresses how among its employees and business partners they could guarantee that goods, inputs, or merchandise imported into Mexico for the manufacture of products or merchandise do not originate from extraction, production, or total or partial manufacturing using prohibited forms of labor, i.e., forced or compulsory labor, including forced or compulsory child labor, under Article 23.6 of the USMCA and the Agreement establishing the merchandise whose importation is subject to regulation by the Ministry of Labor and Social Welfare, published in the Official Gazette (DOF) on February 17, 2023. 4.1 Selection Criteria. There must be documented procedures for the selection, follow-up, and renewal of commercial relationships with business associates or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of business partners must include, indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses, as well as investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and terrorism financing. If the investigation and/or evaluation of any business partner leads to substantial doubts about the veracity of their operations or services, the company must avoid hiring them and, if applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions. Response: Explanatory Notes: Attach the documented procedure for the selection and contracting of new business partners and monitoring of partners already working with them; this includes any client or supplier of goods or services that has a commercial relationship with the industrial park (it is in the next sub-standard where it is requested to differentiate those at risk in your supply chain); ensure you include the following points: a) What information is required from the business partner. b) What aspects are reviewed and investigated in the selection and contracting of suppliers, as well as for the sale of a property, or the rental of an industrial warehouse, storage, etc. c) Indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a business partner is not reliable and thus, conduct a deeper investigation and evaluate if one should work with them.
d) Indicate if you maintain a file for each of your business partners (co-owners, tenants, and suppliers). e) Point out how the services of your suppliers are evaluated and what points are reviewed. f) Updated list with the general data of the companies operating in the industrial park at the time of submitting the registration request (name, Tax ID/RFC, main business activity, indicate if they perform or do not perform foreign trade operations, etc.); in case of adding or removing co-owners or tenants, you must notify the authority. The file must include at least the following: a) Data of the hosting company (name, Tax ID/RFC, main business activity, etc.). b) Simple copy of the articles of incorporation. c) Identification and simple copy of the notarial power of the legal representative. d) Proof of address. e) Commercial references (if applicable). f) Contracts, agreements, and/or confidentiality agreements. g) Security policies. h) In case applicable, certificate or certification number in the security programs to which they belong. 4.2 Security Requirements. The industrial park must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those business partners (co-owning or tenant companies) that perform foreign trade operations. In the case of business partners that intervene in your supply chain, whether as suppliers that provide their services inside the industrial park such as: private security companies, cleaning, maintenance, staffing, landscaping, contractors, installation and maintenance of alarm and closed-circuit television and video surveillance systems, Information Systems and Technology providers, among others, they are obligated to comply with the same supply chain security requirements. The requirements must be based on the Industrial Park Profile established by the AGACE, or in case it exists, the specific Profile for each actor in the supply chain that corresponds to them. The industrial park must request from its business partners the documentation that accredits and proves that they comply with the minimum security standards established in this Industrial Park Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation supporting compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the company must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its business partners, based on their activity within the supply chain. All co-owning or tenant companies must adhere -without exception- to the general security policy and protocol established by the industrial park.
Answer: Explanatory Notes: Describe the procedure that indicates how you carry out the identification of commercial partners that require compliance with minimum security standards. Ensure you include the following points: a) A registry of commercial partners (co-owner or tenant companies and suppliers) that carry out foreign trade operations, intervene in your supply chain, and must comply with security requirements. Mention what type of companies these are. b) Indicate in what documentary form (agreements, contractual clauses, and/or addenda) you ensure that your commercial partners (co-owner or tenant companies and suppliers) comply with security requirements. c) Indicate whether there are agreements, accords, contractual clauses, and/or addenda regarding the implementation of security measures with service providers inside the industrial park, such as: private security, cleaning and maintenance services, cafeteria, landscaping, Information Technology provider, etc. d) Indicate whether you have commercial partners to whom membership in a supply chain security program is required (for example: C-TPAT or any other World Customs Organization Authorized Economic Operator Program), as well as the information and documentation requested of them.
4.3 Commercial partner reviews. The industrial park, through the Security Committee, must conduct periodic security evaluations (as well as those derived from risk situations) of the processes and facilities of business associates based on a risk analysis, to guarantee that they meet the minimum security standards required by the industrial park, based on the Authorized Economic Operator Program. Maintain records of these evaluations that allow verification that processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the industrial park must communicate them to its partner and supplier and provide a reasonable period to address the identified observations or areas for improvement, or, alternatively, take necessary measures to sanction them. Conducting security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program; therefore, in addition to a documented procedure, there must be a program or schedule for the execution of these security reviews or evaluations, prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company is unaware of whether the processes and facilities of its commercial partners are functioning correctly, it puts its supply chain at risk.
Answer: Explanatory Notes: The industrial park must have a documented procedure to conduct evaluations for the verification or review of security requirements in the processes and facilities of commercial partners. Describe the procedure for conducting reviews of your commercial partners, ensuring you include the following points: a) The frequency with which you visit the commercial partner (this must be at least once a year and derived from risk situations). b) Program or schedule for the execution of security reviews. c) Record or report of the verification or review and, if applicable, the corresponding follow-up. d) The verification format(s) must be properly filled out, including the date, name, and position of those participating in the review, signatures, etc. e) Indicate what action measures are taken if commercial partners do not comply with the established security requirements. If you have commercial partners that hold C-TPAT certification or another supply chain security certification program, indicate the frequency with which their status is reviewed, how you record it, and the actions you take if it is detected that it is suspended and/or cancelled, in accordance with what is established in your procedure. The procedure must include: a) Frequency of visits. b) Security review points. c) Preparation of reports. d) Feedback and agreements with the commercial partner. e) Follow-up on agreements. f) Measures in case of non-compliance with requirements. g) Record of evaluations. h) Areas or persons responsible for carrying out this procedure.
5.1 Delivery and receipt of cargo. The industrial park must inform operators/drivers of transport companies that deliver or receive foreign trade merchandise of the security policies and guidelines for entering, circulating, and carrying out loading/unloading maneuvers inside the park. For their part, all companies - without exception - must previously inform the industrial park's security personnel of the names of the transport companies, the type of cargo vehicles and characteristics of the seals or locks normally used, and, if applicable, the operator data so that they can be fully identified from entry into the industrial park until the facilities of co-owner or tenant companies. The industrial park must have an updated database containing all the aforementioned information.
Answer: Explanatory Notes: Security personnel must permanently update the data of transport companies, operators, types of cargo vehicles that daily enter and exit the Industrial Park, as well as the distinctive characteristics of the high-security seals or locks used by the companies located inside it.
6.1 Storage of vehicles, transport means, containers, train cars, trailers, and semi-trailers. If tractors, pickup trucks, vans, dry boxes, refrigerated boxes, box trucks, gondolas, tank cars, rail hoppers, etc., that transport foreign trade merchandise are empty and must overnight and be secured inside the industrial park, they must be secured with an indicative seal, or placed in a common supervised and monitored area to prevent unauthorized access and improper handling. Transport means must not obstruct the internal roadways of the Industrial Park. If due to force majeure, containers, trailers, or semi-trailers must remain for more than one day in the Park, they must remain inside the company that requested the service, or, if the extension and infrastructure of the Park allow, in a common area that complies with the aforementioned security measures. When operational needs require safeguarding any container, trailer, or semi-trailer loaded with foreign trade merchandise, it must be positioned in a secure area monitored by alarm systems and closed-circuit television and video surveillance, to prevent unauthorized access and manipulation of the merchandise; therefore, it must be closed with a high-security lock in accordance with ISO 17712 Standard. When the cargo is stored overnight or for an extended period, measures must be taken to secure the cargo against unauthorized access.
Answer: Explanatory Notes: Indicate whether containers, trailers, and/or semi-trailers, full or empty, are stored inside the Industrial Park for subsequent dispatch, and explain how their integrity is maintained within your facilities.
7.1 Verification of work history. The Industrial Park must have documented procedures to investigate and verify the information stated in the curriculum, criminal records (if company legislation and policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either on its own or through an external company. Similarly, for positions that require it due to their sensitivity and affect the security of the Industrial Park, in accordance with the previously conducted risk analysis, stricter requirements for hiring must be considered, which must be updated periodically. Regarding personnel already working in the company, periodic investigations must be conducted based on the functions and/or sensitivity of the employee's position. All information regarding personnel must be kept in personal files, which must have restricted access.
Answer: Explanatory Notes: Describe the documented procedure for hiring personnel, and ensure you include the following: a) Requirements and documentation demanded. b) Tests and exams requested. Indicate the areas and/or critical positions that have been identified as risky, according to your analysis, and indicate the following: a) Indicate if there are additional requirements for specific areas and/or jobs. Such as criminal records (if legislation and company policies allow), certificate of non-criminal record, socioeconomic studies, clinical toxicological studies (drug use), etc. If applicable, indicate the jobs or work areas where they are required and with what frequency they are carried out. b) Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document. If you use the services of an agency for personnel hiring, indicate if it has a documented procedure for hiring personnel and how you ensure they comply. The procedures for hiring personnel and contractors may include: a) Exhaustive investigations of the work and personal backgrounds of new employees. b) Confidentiality and responsibility clauses in employee contracts. c) Specific requirements for critical positions. d) If applicable, the periodic update of the socioeconomic study or clinical laboratory test of employees working in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors.
7.2 Personnel dismissal procedure. Documented procedures must exist for personnel dismissal that include the delivery of identification and any other item provided to them to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, communication devices, tools, etc.). Likewise, this procedure must include the deactivation in any computer systems, access systems, among others that may exist.
Answer: Explanatory Notes: Describe the procedure for personnel dismissal, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the delivery of identifications, uniforms, keys, and other equipment is performed and confirmed. c) Indicate the control, record, and/or format in which the delivery of material and deactivation in computer systems (if applicable) is identified and ensured (attach if applicable). d) Indicate the type of records of personnel who ended their employment relationship with the Industrial Park, so that in case it was for security reasons, tenant companies, service providers, and/or business associates are warned.
7.3 Personnel administration. The Industrial Park Headquarters must maintain an updated system, control, or database of active employees. Likewise, it must conduct and maintain updated records of affiliation to social security institutions and other legal labor records. In the case where the Industrial Park has personnel hired by its commercial partners and working within its facilities, it must ensure that they meet the same requirements as the rest of its employees.
Answer: Explanatory Notes: Indicate if the industrial park has an updated system, control, or database, both for personnel hired directly and that hired through a service provider company, and ensure it includes, by way of example but not limitation, the following points: a) Full name. b) Updated photograph at least every five years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). d) Affiliation. e) Work history. f) Illnesses. g) Medical exams. h) Training. i) Psychometric exams. j) Toxicological exams. k) Results of periodic evaluations. l) Observations. This personnel must be hired in accordance with the current labor laws and regulations.
8.1 Classification and handling of documents. Procedures must exist to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified, and procedures for its destruction must be established. The Industrial Park must have safeguarded and updated files of the co-owner and tenant companies with which it has a business relationship, as well as all information related to the security of its supply chain. The Industrial Park must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Answer: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed documentation (classification and filing of documents), which must include: a) Control registry for delivery, loan, etc., of documentation. b) Restricted access to the archive area. c) Storage and classification policies. d) An updated security plan that describes the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. e) In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 8.2. Security of Information Technology.
8.2 Security of Information Technology. To protect Information Technology systems against common cybersecurity threats, a company must have sufficient protection to promote security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, companies must ensure that their security software is active and receives periodic updates. In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the company must have established information technology policies, procedures, and standards, which must be communicated through a training program for all employees who handle computer equipment and systems, including topics to prevent attacks through social engineering and all those threats to which they are exposed (malware, baiting, phishing, etc.). Companies that allow employees to connect remotely to a network must employ secure technologies, such as virtual private networks (VPN), to allow employees to access the company intranet securely when outside the office, as well as procedures designed to prevent unauthorized remote access. For the above, written procedures and infrastructure must exist to protect the Industrial Park Headquarters against loss, theft, leak, hacking, and/or ransomware of information; this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of systems, detect inappropriate access, improper manipulation, or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
Answer: Explanatory Notes: Attach the recovery procedure that supports and guarantees the security of your information, in addition to protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which backups are carried out. b) Who has access to them and who authorizes the recovery of information. c) Indicate what type of tests you perform and how often to verify the security of the network, systems, and infrastructure. d) Mention if, to carry out this type of tests or vulnerability scans, you do so through software, a third party, or provider, and, if applicable, indicate the name or corporate name. e) In case vulnerabilities are found, describe the corrective actions that must be implemented. f) Indicate if you share information about cybersecurity threats with your commercial partners participating in your supply chain (for example: communications, bulletins, emails, etc.). g) Systems must be protected by passwords and modified frequently; indicate the procedure for changing them. h) Indicate if there are information security policies for their protection. i) There must be a system to detect and identify the abuse, intrusion, or access of unauthorized persons to your systems, and/or Information Technology data, as well as the abuse of policies and procedures established by the company, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the systems and policies of Information Technology security policies. The Information Technology and cybersecurity policies and procedures must be reviewed annually and updated resulting from an attack or in accordance with situations that may put the company's systems at risk.
Describe the security measures used to allow employees to connect remotely to a network (VPN), to allow employees to access the company intranet remotely when they are outside the office. In the event of allowing employees to use personal devices to perform company work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and there must be a method to securely access the company network. Indicate whether business partners have access to the Industrial Park's computer systems. If so, indicate what programs they use and how they control access to them. Indicate whether the computer equipment has a backup power supply system that allows for business continuity. The procedures regarding the backup of the company's information must also include: a) How and for how long data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in the event of an incident and how to recover information. c) Frequency and location of backup copies and archived information. d) Whether backup copies are stored in sites alternative to the facilities where the data processing center is located. e) Tests of the validity of data recovery from backup copies. The procedures regarding the backup of the Industrial Park's information must also include: a) How and for how long data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in the event of an incident and how to recover information. c) Frequency and location of backup copies and archived information. d) Whether backup copies are stored in sites alternative to the facilities where the data processing center is located. e) Tests of the validity of data recovery from backup copies.
The procedures regarding the protection of the Industrial Park's information must also include: a) An updated and documented policy for the protection of the Industrial Park's computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. b) Detail if you operate with multiple systems (headquarters/sites) and how these systems are controlled. c) Who is responsible for the protection of the Industrial Park's computer system (responsibility should not be limited to one person, but to several, so that each can control the actions of the others). d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and access levels to computer systems are granted (access to sensitive information should be limited to authorized personnel to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements. e) Indicate the elements or format that passwords for accessing Information Technology systems and computer equipment must have, frequency of changes, if there are other authentication methods, and who or which area provides these passwords. f) Indicate the name of the firewall and antivirus used, providing evidence that this security software is active and receives periodic updates. Therefore, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses. All computer equipment, electronic media (hard drives, cell phones, etc.) and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipment must be disposed of, there must be a documented procedure that includes how they must be formatted, sanitized, or destroyed appropriately to avoid information leakage.
g) In the event of employee termination, access to computer equipment, telecommunications, and the network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. h) Measures planned to handle incidents in case the system is compromised. 9. Security training and awareness. You must have a documented awareness program on threats established, designed, and updated by the Security Committee to recognize and create awareness about threats from terrorists and smugglers at each point in the supply chain. The training program must be comprehensive and cover all security requirements of the Authorized Economic Operator Program. Employees must know the established procedures of the industrial park to consider a risk situation and know how to report it. Additional training must be provided to employees in areas with access and exits from the facilities. 9.1 Training and awareness on threats. The Industrial Park must have a training and awareness program on supply chain security policies directed at all its administrative and security employees; additionally, make informational material available regarding the established procedures in the Industrial Park to consider a situation that threatens its security and how to report it. Training records must include the date of the training, the names of the attendees, and the topics of the training. Similarly, security personnel must be offered training according to their functions to help the companies installed in the Industrial Park maintain the integrity of their cargo, recognize internal conspiracies, and protect access controls. In addition to security training programs, a program on awareness of alcohol and drug consumption must be included. Furthermore, personnel must be trained in the company's cybersecurity policies and procedures, including access to computer equipment and systems via passwords or passphrases; personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and periodic update programs must be maintained. Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the Industrial Park Corporate Office and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives. Response: Explanatory Notes: You must have a training program on security and prevention in the supply chain for all employees. Briefly explain what it consists of and ensure you include the following: a) Brief description of the topics taught in the program. b) When they are taught (onboarding, specific periods, etc.). c) Frequency of training and, if applicable, updates. d) Indicate how participation in supply chain security training is documented.
e) Explain how employee participation in security matters is encouraged (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all its objectives. Training to perform reviews of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments. b) Hidden smuggling in natural compartments. c) Signs of pest contamination. d) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit. e) Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials, and the identification of infested wood (imports); therefore, describe how you comply with the provisions established by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144 SEMARNAT-2017, in accordance with International Standard for Phytosanitary Measures No. 15, known as Regulation of Wood Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. 10. Handling and investigation of incidents. There must be documented procedures to report and investigate security incidents in the supply chain, the actions to be taken to prevent their recurrence, as well as to notify security personnel, business partners who may be part of the affected supply chain, security specialist or contact of the Authorized Economic Operator Program, and/or other competent authorities. Reporting and investigation procedures must include updated contact information or directory listing the names and phone numbers of personnel requiring notification. The investigation and analysis of incidents must be documented (physical and/or electronic file), as well as corrective actions to prevent recurrence, which must be implemented as soon as possible. 10.1 Reporting of anomalies and/or suspicious activities. In the event of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with your logistical processes (related to access control, delivery, receipt, and storage of merchandise, security inspections of cargo vehicles and transport operators, etc.), these must be reported to the security personnel of the Industrial Park Monitoring Center, business partners who may be part of the affected supply chain, security specialist or contact of the Authorized Economic Operator Program, and competent authorities, keeping a record of such anomalies and/or unusual activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities and ensure you include the following: a) Who is responsible for reporting incidents. b) Detail how you determine which authority to communicate with in different scenarios or presumption of suspicious activities. c) Mention if you keep a record of the reporting of these activities and/or suspicions and briefly describe what it consists of. 10.2 Investigation and analysis. There must be a written procedure to denounce or report anomalies and/or suspicious activities, as well as for the analysis and investigation of incidents related to cargo security that may occur inside the industrial park to determine their cause, in addition to corrective actions to prevent recurrence, which must be implemented as soon as possible. The information derived from the investigation conducted jointly by the Industrial Park Monitoring Center and by the security managers of the affected company must be documented and available at all times for authorities that require it. Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in the event of any incident related to cargo security and ensure you include the following: a) Responsible for carrying out the investigation. b) Documentation that integrates the incident security investigation file. The documents in the file derived from the investigation must include at least the following: a) General information of the shipment, service order. b) Transport request; confirmation of transport medium; identification of the transport operator (access records, exit records, security inspection records, etc.). c) Transport medium Inspection Formats; exit orders; records of collection, delivery, and receipt of foreign trade merchandise. d) Videos from alarm systems, closed-circuit television, and video surveillance. e) Documentation generated by and for business partners and customs authorities. f) Tracking and monitoring report of the unit (GPS tracking).
E11. Profile of the General Warehouse of Deposit. Acknowledgment of Receipt First Time: Renewal: Addition: Modification: The data you provide will replace the data you provided when you requested your authorization. General Information The objective of this Profile is to ensure that general warehouses of deposit have security practices and processes implemented in their facilities, focused on strengthening the supply chain and mitigating the risk of contamination of shipments with illicit products. General warehouses of deposit interested in obtaining the authorization referred to in rule 7.1.5. must demonstrate that they have documented and verifiable processes; likewise, they must integrate the criteria required in this document according to the business model or design they have established, seeking during the implementation of security standards, the application of a risk analysis culture supported by decision-making in accordance with the values, mission, vision, codes of ethics, and conduct of the general warehouse of deposit itself. Filling Instructions:
You must fill out a Profile of the General Warehouse of Deposit for each of the installations that the general warehouse of deposit determines will be subject to certification, whether direct or enabled for a third party to operate them under the authorization. The Profile presented must coincide with the installation manifested in your application for registration as a certified business partner under the general warehouse of deposit modality and with the address(es) registered with the Taxpayer Registry Code (RFC).
In each sub-standard, the general warehouse of deposit must detail how it complies with or exceeds what is established in each of the sections as indicated.
The format of this document is divided into two sections, as detailed below:
Standard. Description of the standard 1.1 Sub-standard. Description of the sub-standard Response. Explanatory Notes. Describe and/or attach... a) Points to highlight...
Indicate how you comply with what is established in each of the sub-standards; therefore, you must attach the procedures in Spanish that are required, if applicable, or provide a detailed explanation of what is requested in the Response field. The section regarding Explanatory Notes is a guide regarding the points that must be included in the Response or in the attached procedures, depending on the case of each sub-standard, indicating in an indicative manner those points that should not be excluded from your response.
Once this Profile of the General Warehouse of Deposit is answered, you must attach it to the Application for Registration in the Business Certification Scheme referred to in rule 7.1.5., fraction VII. For the purpose of verifying what is stated in the previous paragraph, the Tax Administration Service (SAT) through the AGACE may carry out an inspection of the installation indicated here, with the exclusive purpose of verifying what is stated in this document.
Any incomplete Profile of the General Warehouse of Deposit will not be processed.
Any question related to the Application for Registration in the Business Certification Scheme and the Profile of the General Warehouse of Deposit, please direct it to the contacts that appear on the SAT Portal.
In the event of being authorized with the Registration in the Business Certification Scheme, this format must be kept updated and notify when the circumstances under which the registration was granted have varied and as a result changes or modifications are required in the information provided and stated in this Profile of the General Warehouse of Deposit to the authority, in accordance with what is established in rule 7.2.1., fourth paragraph, fractions I, II, and VII.
When, as a result of the inspection visit, non-compliances related to minimum security standards result, the applicant may remedy them before the issuance of the resolution established in rule 7.1.6., for which they will have a maximum period of three months counted from the notification of the non-compliances indicated. Installation Data A Profile of the General Warehouse of Deposit must be filled out for each of the installations that belong to and operate under the same RFC and that the general warehouse of deposit determines will be subject to certification, provided they have authorization to provide the service of storing merchandise destined for the fiscal deposit regime, regardless of whether they are direct or enabled. Installation Information: Profile Number of the General Warehouse of Deposit: of RFC: Name and/or Legal Name: Name and/or Denomination of the Installation: (If it does not exist, make the corresponding clarification and justification) Type of Installation: Street Number and/or exterior letter Interior Number and/or letter Neighborhood Postal Code Municipality/Alcaldía Federal Entity Age of the installation (years of operation to provide merchandise storage services operated by the applicant): Activities carried out in the installation: Preponderant products handled in the General Warehouse of Deposit (as appropriate):
Average monthly number of credit letters issued: Average monthly number of extraction declarations: Total number of employees at this facility: Facility Surface Area (m²): Certifications in security programs (indicate if this facility holds a certification for any of the following programs). CTPAT Yes No Level: Pre-Applicant: Applicant: Certified: Certified/Validated: CTPAT Account number (Eight digits): Date of last visit to this facility: Authorized Economic Operator from other countries (AEO) Yes No Program: Registration: Other Supply Chain Security Programs Yes No Program: Registration: Certifications (indicate if you hold certifications that you consider impact your supply chain process, e.g., ISO 9000, ISO 28000, among others). Name: Category: Validity: Name: Category: Validity:
Answer: Explanatory Notes: Indicate which are the sources of information used to qualify risks during the analysis phase. Attach the risk matrix, as well as the documented procedure to identify risks in the supply chain and the facilities of the general warehouse, which must include at least the following points: a) Frequency with which the risk analysis is reviewed and/or updated. b) Aspects and/or areas of the general warehouse that are incorporated into the risk analysis. c) Methodology or techniques used to perform the risk analysis. d) Persons responsible for reviewing and/or updating the risk analysis of the general warehouse. Likewise, the documented procedure to identify risks in the supply chain and its facilities must contemplate the risk assessment and management process, and include the following aspects: a) Establishment of a context (cultural, political, legal, economic, geographic, social, etc.). b) Identification of risks in its supply chain and its facilities. c) Risk analysis (causes, consequences, probabilities and existing controls to determine the level of risk as high, medium and low). d) Risk evaluation (decision making to determine the risks to be treated and priority to implement the treatment). e) Risk treatment (application of alternatives to change the probability of risks occurring). f) Risk monitoring and review (monitoring of the results of the risk analysis and verification of the effectiveness of its treatment). It is suggested to use risk administration, management, and evaluation techniques according to international standards ISO 31000, ISO 31010, and ISO 28000 that, according to its business model, it should implement.
1.2 Security Policies. The general warehouse must have a policy oriented towards preventing, securing, and recognizing threats to the security of the supply chain and warehouse facilities, such as drug trafficking, human smuggling, money laundering, arms trafficking, prohibited goods, acts of terrorism, as well as those threats associated with information exchange. Such policies must be reflected in the corresponding procedures and/or manuals. To promote a culture of security, the general warehouse must demonstrate its commitment to supply chain security and the Authorized Economic Operator Program through a statement highlighting the importance of protecting the flow of national and international commerce from criminal activities, established through the security policy. The senior officials or executives of the warehouse who must endorse and sign the security policy can be the company president, the chief executive officer, the general manager, or personnel with an equivalent position with decision-making authority. Answer: Explanatory Notes: State the security policy oriented towards preventing, securing, and recognizing threats in the supply chain and facilities of the general warehouse, indicate who is responsible for its review, signature, and dissemination to employees, as well as the frequency with which its update is carried out. This policy must be communicated to employees through a program and/or dissemination campaign. The security policy must be signed by a senior official of the general warehouse and be displayed in various areas of the company, including the company website, posters in key areas of the company (reception, shipments, receipts, warehouse, etc.), and as part of the initial training and reinforcement of the company. 1.3 Internal Audits in the Supply Chain. In addition to routine monitoring in control and security, it is necessary to schedule and carry out audits at least once a year, under the guidelines of a documented procedure that allows evaluating all processes regarding security in the supply chain and its facilities in a more critical and deep manner, as well as ensuring that its employees follow the warehouse's security procedures. The audits must be carried out by the Security Committee of the general warehouse and a documented procedure must be established, as well as a program or calendar for their execution. Although it is necessary that the audits are focused on supply chain security and based on the evaluation, review, and execution of minimum security standards, their focus must be adjusted to the size of the organization, business model, variation between facilities, and level of risk, identified during the analysis according to sub-standard 1.1. Audits can be general or focus on specific areas or processes according to their work program. The objective of an internal audit focused on the Authorized Economic Operator Program is to verify and ensure that employees follow the general warehouse's security procedures. The review process does not have to be complex; however, the formats and records used for the application of these reviews must evidence that the application and execution of the evaluated processes were validated, in addition to the corresponding follow-up of identified observations. The warehouse's senior management must review the audit results, analyze the causes, and undertake corrective or preventive actions required. The audit process must ensure that the necessary information is collected to allow management to perform this evaluation. The review must be documented, in addition to the fact that the company's points of contact must provide and register periodic updates on the process or results of any audit, exercise, or validation.
Answer: Explanatory Notes: Describe the documented procedure to carry out an internal audit, focused on security in the supply chain, ensure to include the following points: a) Indicate how the general warehouse carries out the scheduling or calendarization to perform internal audits regarding security in the supply chain. b) Indicate who participates in them and the records that are generated, as well as the frequency with which they are carried out. c) Indicate how the management of the general warehouse verifies the results of the audits regarding security of the supply chain and how it carries out and/or implements preventive, corrective, and improvement actions in addition to the follow-up and closure of the same. d) The formats used during internal audits must be duly filled out and through them, evidence that the procedures and security measures are being put into practice. 1.4 Contingency and/or Emergency Plans. There must be a documented contingency and/or emergency plan; this plan must address crisis management, security recovery plans, and business resumption to ensure business continuity in case of a situation that affects the normal development of activities and foreign trade operations of the warehouse in its supply chain (facilities and during the receipt, storage, custody, and extraction of merchandise destined for the tax warehousing regime and national merchandise according to its logistical process). A crisis or contingency may include the interruption of commercial data movement due to a cyberattack, a fire, the kidnapping of a transport driver by armed individuals, theft and/or damage to merchandise, theft and/or damage to labels and/or tags, chemical spills, a bomb threat, the detection of suspicious packages, power outages, non-arrival of merchandise, blockages or road closures, threats or extortion, a customs closure, among others. Such plans must be communicated to employees through a program and/or dissemination campaign, as well as carrying out tests, practical exercises, and annual simulations of the supply chain's contingency and emergency plans to verify their effectiveness, and of which it must keep a duly filled-out and signed record (for example: result reports, minutes, or reports, which must be backed by video recordings, photographs, etc.) demonstrating their execution. The contingency and/or emergency plan must be updated as necessary, based on changes in operations and the risk level of the general warehouse. Answer: Explanatory Notes: Attach the documented contingency and/or emergency procedure or plan, to ensure business continuity in case of an emergency or security situation, that affects the normal development of activities in the facilities, during the receipt, storage, custody, and extraction of merchandise destined for the tax warehousing regime and national, according to its logistical process in the supply chain.
This procedure must include, by way of example and not limitation, the following: a) What situations it contemplates, describing the action plan and steps to be followed in case of crisis, as well as the tasks that personnel have assigned during the handling of such contingencies. b) What mechanisms it uses to disseminate and guarantee that the business continuity plan is effective. c) Contemplate the scheduling and execution of tests, practical exercises, and annual simulations and how they are documented (for example: result reports, minutes, or reports, which must be accompanied by video recordings, photographs, etc., demonstrating their execution). 2. Physical Security. The general warehouse must have established mechanisms and documented processes to prevent, detect, or deter the entry of unauthorized personnel into the facilities. All sensitive areas of the general warehouse must have physical barriers, as well as control and deterrence elements against unauthorized access. 2.1 Facilities. Facilities must be constructed with materials that can resist unauthorized access. Periodic documented inspections must be carried out to maintain the integrity of the structures and in case any irregularity has been detected, the corresponding repair must be carried out as soon as possible by the personnel designated for these tasks. Likewise, the territorial limits, as well as the various accesses, internal routes, and the location of the buildings must be fully identified. Answer: Explanatory Notes: Indicate the predominant materials with which the installation is constructed (for example: steel structure with cement walls, brick walls, concrete, among others), and indicate how the review and maintenance of the integrity of the structures is carried out. Indicate the personnel or area responsible for carrying out the tasks of inspection, maintenance, and repair of damages to the facilities. Attach a distribution or architectural plan of the whole, where the limits of the installation, access routes, emergency exits, location of buildings, critical areas, parking, and boundaries can be identified.
2.2 Accesses in Doors and Booths. The entrance or exit doors of personnel and/or vehicles of the general warehouse facilities must be attended, controlled, watched, and/or supervised either by own personnel or by security personnel. The number of access doors must be kept to the minimum necessary. Access to sensitive areas must be restricted according to the job description or assigned tasks. Answer: Explanatory Notes: Indicate how many doors and/or accesses exist in the facilities, as well as the operating hours of each one and indicate how they are monitored and/or supervised (in case of having assigned surveillance personnel, indicate the quantity). Detail if there are blocked doors and/or accesses, or permanently closed and their location. Describe how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of records and controls you use). 2.3 Perimeter Fences. Perimeter fences and/or peripheral barriers must be installed to secure the perimeters of the general warehouse facilities, and particularly, the areas for receipt, storage, custody, and extraction of merchandise destined for the tax warehousing regime, national merchandise, high value, hazardous, areas with restricted access, and others determined according to its risk analysis, with the object of preventing merchandise theft and unauthorized entries. These must be inspected regularly and keep a record of the review with the aim of ensuring their integrity and identifying damages, which must be repaired as soon as possible by the personnel designated for these tasks. The storage, high value, hazardous, and/or restricted access areas must be clearly identified and monitored to prevent unauthorized entries. Answer: Explanatory Notes: Describe the type of peripheral barrier and/or fences with which the installation is equipped, ensure to include the following points: a) Specify which areas it segregates in the installation by being considered critical and/or sensitive. b) Point out their characteristics (material, dimensions, etc.). c) In case of not having fences, please justify the reason in detail. d) Frequency with which the integrity of the perimeter fences is verified, and the records that are carried out with the aim of ensuring their integrity and identifying damages, which must be repaired as soon as possible. e) Indicate the personnel or area responsible for carrying out the tasks of inspection and repair of damages.
Describe how the cargo destined for foreign countries, hazardous material, and high value cargo is segregated; ensure to include the following points: a) Indicate how you control and separate merchandise destined for the tax warehousing regime, national merchandise, and if it is additionally identified (for example: labels, different packaging, tickets, among others). b) Identify and point out the restricted access areas (hazardous merchandise, high value, label placement, labeling, sub-maquila, confidential, etc.). The procedure for the inspection of perimeter fences could include: a) Personnel responsible for carrying out the process. b) How and how often the inspections of fences, perimeter fences, and/or peripheral barriers are carried out. c) How the inspection record is kept. d) Who is responsible for verifying that the repairs and/or modifications meet the technical specifications and necessary security requirements. 2.4 Parking Lots. Access to the facilities' parking lots must be controlled and monitored by security personnel or designated for this task according to applicable provisions. Private vehicles (of employees, visitors, suppliers, and contractors, among others) must be prohibited from parking within the merchandise handling and storage areas, as well as in adjacent areas. Answer: Explanatory Notes: Describe the procedure for the control and monitoring of parking lots, ensure to include the following points: a) Persons responsible for controlling and monitoring access to the parking lots. b) Identification of the parking lots (specify if the visitor and employee parking is separated from the merchandise storage areas). c) How the entry and exit control of vehicles to the facilities is carried out, indicate the records that are made for parking control and the existing control mechanisms (for example: ticket stubs, card readers, badges, etc.), how they are assigned and the area responsible for doing so. d) Policies or mechanisms to not allow the entry of private vehicles to the merchandise storage areas.
2.5 Control of keys and lock devices. Windows, doors, as well as inner and outer fences, according to their risk analysis, must be secured with locking devices. The general warehouse deposit must have a documented procedure for the handling and control of keys and/or locking devices for the inner areas considered critical. Likewise, they must keep a register and establish signed liability letters from persons who have keys or authorized access according to their level of responsibility and tasks within their work area. Response: Explanatory Notes: Indicate if all doors, windows, inner and outer entrances have closing or security mechanisms. Attach the documented procedure for the handling, safeguarding, assignment, control, and non-return of keys for the facilities, offices, and critical and/or sensitive areas. The procedure must include the following points: a) Persons responsible for administering and controlling the security of the keys. b) Format and/or control register for the loan of keys. c) Treatment of loss or non-return of keys. d) Indicate if there are areas where access is granted with electronic devices and/or any other access mechanism.
2.6 Lighting. Lighting inside and outside the facilities must allow for clear identification of persons, material, and/or equipment located there, including the following areas: entrances and exits, handling, loading, unloading, and storage areas for merchandise, perimeter and/or peripheral walls, inner fences, and parking areas, and must have an emergency and/or backup lighting system in sensitive areas. Response: Explanatory Notes: Describe the procedure for the operation and maintenance of the lighting system. Ensure you include the following points: a) Indicate which areas are illuminated and which have an emergency and/or backup system (indicate if you have an auxiliary power plant or any other mechanism to supply electricity in case of any contingency). b) How do you ensure that the lighting system has continuity in the event of a lack of supply in each of the areas of the facility and with special emphasis on the areas considered critical and/or sensitive, in such a way that it allows clear identification of the personnel, material, and/or equipment located there. c) Person responsible for the control and maintenance of the lighting systems. d) Maintenance and review program (if it coincides with another process, indicate it). The procedure may include: a) How the lighting system is controlled. b) Operating hours. c) Identification of areas with permanent lighting.
2.7 Communication devices. The general warehouse deposit must have communication devices and/or systems with the purpose of contacting security personnel and/or authorities immediately when required in case of an emergency and security situation. Additionally, it must have a backup system and verify its proper functioning periodically. Response: Explanatory Notes: Describe the procedure that personnel must perform to contact the security personnel of the general warehouse deposit or, in its case, the corresponding authority in case of any security incident. Indicate if operational and administrative personnel have or have access to devices (landline phones, mobile phones, alert and/or emergency buttons, etc.) to communicate with security personnel and/or the corresponding person (these must be accessible to users to be able to react promptly). Indicate what type of communication devices the security personnel of the general warehouse deposit uses (landline phones, cell phones, radios, alarm system, etc.) Describe the procedure for the control and maintenance of communication devices, ensure you include the following points: a) Policies for the assignment of mobile communication devices. b) Maintenance or replacement program for fixed and mobile communication devices. c) Indicate if you have backup communication devices in case the permanent system fails and, if so, briefly describe them. The procedure may include: a) Person responsible for the proper functioning and maintenance of communication devices. b) Verification and maintenance register of the devices. c) Method of assignment of communication devices.
2.8 Alarm systems, closed-circuit television, and video surveillance systems. Alarm systems, closed-circuit television, video surveillance systems, and security technologies must be used to monitor, notify, or deter unauthorized access and prohibited activities in the facilities and other areas considered sensitive, notify the corresponding area, and also be used as evidence in investigations derived from any security incident. These security systems and technologies must be placed according to a prior risk analysis, in such a way that it allows clear identification of the area or environment being monitored, to monitor and supervise areas involving the entry and exit of authorized personnel, visitors, suppliers, areas involving the handling, loading, unloading, custody, and storage of merchandise destined for the fiscal and national deposit regime, security inspections of cargo vehicles, yards for transport means, parking for private vehicles, as well as areas considered critical and/or sensitive on a permanent and uninterrupted basis in accordance with their operation. The general warehouse deposit must have documented operating procedures for the aforementioned systems. In the case of alarm systems, closed-circuit television, video surveillance systems, and security technologies, the procedure must include the supervision of the good condition of the equipment, indicating the frequency with which recordings must be backed up, the persons responsible for their operation, and the verification of the correct position of the cameras. Alarm systems, closed-circuit television, and video surveillance systems must allow clear identification of the area or environment being monitored, be recording permanently, and maintain a backup of recordings for at least one month, considering that, in the case that their logistical processes exceed this period, the period for maintaining these backups must be increased in order to have the necessary elements to assign corresponding responsibilities in case of a security incident. Such systems and all security technology infrastructure must have restricted access. Alarm systems, closed-circuit television, and video surveillance systems, and the security technologies of the general warehouse deposit must comply with what is established in rule 4.5.18., so that the customs authority has access to the points of delivery of the merchandise, as well as exit points, as determined by ANAM. Response: Explanatory Notes: Mention the documented procedure in which you indicate the functioning of the external central alarm system or sensors, and if so, describe the following points: a) Indicate if doors and windows have alarm sensors, as well as the areas where motion sensors are available. b) Procedure to follow in case an alarm is activated. c) Indicate the personnel or area responsible for maintenance, how failures are reported, and the registers they use. Describe the documented procedure for the operation of alarm systems, closed-circuit television, video surveillance systems, and security technologies (this must be reviewed and updated annually and according to the risk analysis or circumstances), ensure you include the following points: a) Indicate the number of security cameras of the alarm systems, closed-circuit television, and video surveillance systems installed, technical characteristics, and their location by area (detail if they cover the entry and exit points of the facilities to cover the movement of vehicles and individuals, and where the inspection mentioned in sub-standard 7.2 is carried out, as well as the storage place of merchandise destined for the fiscal and national deposit regime). Attach a layout or map of the distribution of security cameras.
b) Indicate the location of the alarm systems, closed-circuit television, and video surveillance systems, and security technologies, where the monitors are located, who reviews them, as well as operating hours, and if applicable, if there are remote monitoring stations. All security technology infrastructure must be physically protected against unauthorized access. c) Perform periodic and random reviews of the recordings. Indicate how they review them (random, every week, special events, restricted areas, etc.), who is the designated personnel, and if management is involved in the reviews. The results of the reviews must be documented to include corrective actions for audit purposes. d) Indicate for how long these recordings are kept (must be at least one month). e) Alarm systems, closed-circuit television, and video surveillance systems, and security technologies must have an alternative energy source that allows them to continue functioning in case of an unexpected loss of direct power. Therefore, indicate if the alarm systems, closed-circuit television, and video surveillance systems are backed up by an emergency power plant or any other mechanism to supply electricity that guarantees their functioning. These systems should have an alarm/notification function, indicating a failure condition in the functioning and/or recording, indicate if their systems have such a function. f) Indicate if, in addition to the alarm systems, closed-circuit television, and video surveillance systems, you use any other type of technology to strengthen the security measures already in place. g) Describe the procedure implemented to regularly test and inspect the alarm systems, closed-circuit television, video surveillance systems, and security technologies and ensure their proper functioning. The results of the inspections and functional tests must be documented, as well as the necessary corrective actions (these must be implemented as soon as possible). Additionally, the documented results of these inspections must be kept for a sufficient time for audit purposes. h) Indicate if the provider of alarm systems, closed-circuit television, and video surveillance systems has access to the security cameras, if they are in charge of monitoring them, how access is controlled, and who is responsible for said monitoring.
c) Indicate how contracted personnel by a business partner working within the facilities are identified (contractors, subcontractors, in-house services, personnel from merchandise handling companies, sub-maquila, etc.) The procedure must also describe how the general warehouse deposit delivers, changes, and withdraws employee identifications and access controls, ensure you include the areas responsible for authorizing and administering them. Indicate how you ensure that access to sensitive areas is restricted according to the job description or assigned tasks (include the type of registers and controls you use). Attach the documented procedure for the control of identifications. 3.3 Identification of visitors and suppliers. To have access to the facilities, visitors and suppliers must present official identification with a photo for documentation upon arrival and a register must be kept. All visitors and suppliers must receive a temporary identification, be accompanied by warehouse personnel during their stay in the facilities, and ensure that the visitor/supplier always wears the provisional identification provided in a visible place; said procedure must be documented. In the case of suppliers and users who work regularly in the facility, the general warehouse deposit must have a mechanism or system for controlling identification badges. Response: Explanatory Notes: Describe the procedure for controlling access for visitors and suppliers, ensure you include the following points: a) Indicate what registers are kept (personal formats for each visit, logbooks, among others). b) The register of visitors and suppliers must include the following:
3.4 Procedure for identification and withdrawal of unauthorized or identified persons or vehicles. The general warehouse deposit must have documented procedures that specify how to identify, confront, or report unauthorized or identified persons and/or vehicles; said procedure must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Attach the documented procedure to identify, confront, or report unauthorized or identified persons and/or vehicles. The procedure must include: a) Personnel in charge of carrying out the procedure. b) Designate a person or area responsible for being informed of security incidents. c) Instructions for confronting and addressing unidentified personnel. d) Indicate in which cases the corresponding authorities must be reported. e) How the register of security incidents and the measures adopted in each case is carried out. 3.5 Courier and package deliveries. Courier and packages destined for general warehouse deposit personnel must be registered and examined upon arrival and departure before being distributed to the corresponding area and destinations. Likewise, the company must have a documented procedure for the reception and review of courier and packages, which must be communicated to responsible personnel through training. The training must be documented. Response: Explanatory Notes: Describe the procedure for the reception and review of courier and packages, and ensure you include the following: a) Personnel in charge of carrying out the procedure. b) Indicate how you identify the personnel or provider of the courier and package service (indicate if an additional procedure to the supplier access procedure is required). c) Indicate how the review of the courier and/or packages is carried out, what mechanism you use, the registers kept, and if so, the incidents detected. d) Describe the characteristics or elements to determine if courier and/or packages are suspicious. e) Indicate what actions you take in case of detecting suspicious courier and/or packages.
4.1 Selection criteria. There must be documented procedures for the selection, follow-up, or renewal of commercial relationships with business associates and/or suppliers, which include interviews, reference verification, evaluation methods, and use of provided information. The information derived from the investigation and/or evaluation of business associates and/or suppliers must be documented and integrated into a file (physical or electronic). The procedure for the selection of commercial partners must include indicators to identify clients or suppliers that may not be legitimate or with unlocated addresses, in addition to investigations, reviews, or evaluations of said partners for the identification and control of activities related to money laundering and the financing of terrorism. If the investigation and/or evaluation of any commercial partner leads to substantial doubts about the veracity of their operations or services, the general warehouse deposit must avoid hiring them and, where applicable, notify its security specialist or Authorized Economic Operator Program contact and the corresponding authority about its suspicions.
Response: Explanatory Notes: Attach the documented procedure for the selection and hiring of new commercial partners and monitoring of partners with whom it is already working, this comprises any type of supplier that has a relationship with its logistics process and its supply chain (it is in the following sub-standard where it is requested to differentiate those at risk in its supply chain), likewise, with potential and predominant clients to hire its service frequently and/or those who have a commercial relationship with the general warehouse deposit. Ensure to include the following points: a) What information is required from its commercial partner. b) What aspects are reviewed and investigated (the result of the investigation must be integrated into the file). c) The indicators to identify clients or suppliers that may not be legitimate (payments above the standard rate, in cash; having little knowledge of the merchandise to be shipped; being evasive; minimal contact information (cell phone, contact points, emails, among others); recently created companies or businesses without commercial history, etc.) or with unlocated addresses. This point refers to pointing out all those alerts to determine that a commercial partner is not reliable and thus, carry out a deeper investigation and evaluate if it should work with him. d) Indicate if it maintains a physical or electronic file of each of its commercial partners, as well as the information it must contain. e) Point out how the services of its commercial partner are evaluated and what points it reviews. The file must include at a minimum the following: a) Company data (name, RFC, activity, etc.). b) Legal representative data. c) Proof of address. d) Commercial references (where applicable). e) Contracts, agreements, and/or confidentiality agreements. f) Security policies. g) Where applicable, certificate or certification number in the security programs to which it belongs.
4.2 Security requirements. The general warehouse deposit must have a documented procedure in which, according to its risk analysis, it requests additional security requirements from those commercial partners that intervene in the service provided by said warehouse and in its supply chain, whether as providers of pallets and supplies for the packaging and/or packing of merchandise, providers of high-security seals, as well as service providers that also intervene in the control, manipulation, transfer, and/or storage of merchandise destined for the tax deposit and national regime as: cleaning service providers, private security, personnel hiring, storage, loading, unloading, and cargo handling service providers, collection and recycling, high-security seal providers, installation and maintenance of alarm, closed-circuit television, and video surveillance systems, subcontractors, and where applicable, transporters for the transfer and/or distribution of merchandise destined for the tax deposit regime, and those who handle import and export documentation, such as customs brokers, among others. The requirements must be based on the General Warehouse Deposit Profile established by the AGACE generically, or in case it exists, the specific Profile for each actor in the supply chain that corresponds to it. The general warehouse deposit must request from its commercial partners the documentation that accredits and proves that it complies with the minimum security standards established in this General Warehouse Deposit Profile, either through a written declaration issued by the legal representative of the partner, agreements or contractual clauses, backed by documentation that supports compliance with the requirements established in the Authorized Economic Operator Program. Likewise, the warehouse must take into account and know the specific requirements of the Authorized Economic Operator Program that will be applicable to each of its commercial partners, based on their activity within the supply chain. In the case of commercial partners of the general warehouse deposit that provide their services within the facilities, they must be obliged to comply with these supply chain security requirements.
Response: Explanatory Notes: Describe the procedure that indicates how it carries out the identification of commercial partners that must comply with minimum standards in terms of security. Ensure to include the following points: a) A register of commercial partners that must comply with security requirements, and mention what type of providers these are (transporters for the transfer and/or distribution of merchandise destined for the tax deposit regime, cleaning service providers, cafeteria, private security, material suppliers, personnel hiring, storage, loading, unloading, and cargo handling service providers, subcontractors, etc.). b) Indicate in what documentary form (agreements, accords, contractual clauses, and/or addenda) it ensures that its commercial partners comply with security requirements. c) Indicate if there are agreements, accords, contractual clauses, and/or addenda regarding the implementation of security measures with its service providers inside the general warehouse deposit, such as: customs brokers, private security, cleaning and maintenance services, cafeteria, gardening, Information Technology providers, etc. d) Indicate if it has commercial partners to whom it is required to belong to a supply chain security program (for example: CTPAT, or any other World Customs Organization Authorized Economic Operator Program) as well as the information and documentation requested of them.
4.3 Commercial partner reviews. The general warehouse deposit through the Security Committee must carry out periodic security evaluations (as well as those derived from risk situations), of the processes and installations of business associates based on a risk analysis to guarantee that they have the minimum security standards required by the warehouse, based on the Authorized Economic Operator Program, maintain records of them, which allow to verify that the processes and security measures are being executed, as well as the corresponding follow-up. When inconsistencies are found, the general warehouse deposit must communicate them to its partner and/or supplier and provide a justified period to address the observations or areas of opportunity identified, or otherwise, have the necessary measures to sanction it. Carrying out security evaluations of commercial partners is important to guarantee that there is a solid and functioning security program, which is why, in addition to a documented procedure, there must be a program or calendar for the execution of said security reviews or evaluations prioritizing partners that are more critical according to their risk analysis. If a member is not evaluated and the company does not know if the processes and installations of its commercial partners function correctly, it puts its supply chain at risk.
Response: Explanatory Notes: The general warehouse deposit must have a documented procedure to carry out evaluations for the verification or review of security requirements in the processes and installations of commercial partners. Describe the procedure to carry out reviews of its commercial partners, ensuring to include the following points: a) Periodicity with which it visits the commercial partner (this must be at least once a year and derived from risk situations). b) Program or calendar for the execution of security reviews. c) Records or reports of the verification or review and, where applicable, the corresponding follow-up. d) The verification formats must be properly filled out, placing the date, name, and position of those participating in the review, signatures, etc. e) Point out what action measures are taken in case commercial partners do not comply with the established security requirements. In case of having commercial partners that have CTPAT certification or another supply chain security certification program, indicate the periodicity with which its status is reviewed, how it registers it, and the actions it takes in case it is detected that it is suspended and/or canceled according to what is established in its procedure. The procedure must include: a) Periodicity of visits. b) Area or person responsible for carrying out this procedure. c) Points of review in terms of security. d) Report preparation. e) Feedback and agreements with the commercial partner. f) Follow-up to agreements. g) Measures in case of detection of non-compliance with requirements. h) Record of evaluations.
5.1 Process mapping. There must be a map that shows step by step the logistics process of the flow of merchandise destined for the tax deposit regime during its deposit, handling, and custody, as well as the documentation required through the international supply chain (credit letters, extraction customs entries, etc.). The general warehouse deposit must take into account and include within its mapping all parties involved in its supply chain, containing additional warehouses, warehouses, or distribution centers (direct and/or authorized), and where applicable, those that handle import and export documentation, such as customs brokers, others that may have operational control such as transporters, etc. If within its supply chain any part of the transport is subcontracted, it is indispensable that it be considered within its risk analysis and process mapping, since the more direct and indirect suppliers, the greater the risk involved.
Response: Explanatory Notes: Attach the process map where the flow through which import and export merchandise destined for the tax deposit regime passes is illustrated and described, from entry into the warehouse until the extraction of the merchandise, and where applicable, having well identified the transfer of merchandise destined for the tax deposit regime to a different warehouse or storage facility (authorized or direct) by request of some client, as well as the transfer or transfer of cargo when appropriate. Likewise, it is necessary to include a procedure to carry out value-added operations on the merchandise (placement of labels, labeling, packaging for display or sale, etc.). And where applicable, those that handle import and export documentation, such as customs brokers, others that may have operational control such as transporters, etc. This process map must contain at least the following aspects: a) Quotation. b) Service contract. c) Issuance and transmission of the credit letter through its electronic system to that of the Tax Administration Service. d) Arrival of merchandise at the general warehouse deposit. e) Merchandise receipt process. f) Generation of fiscal and/or identification labels. g) Integration of customs documentation, for example:
5.2 Direct and authorized warehouses, distribution centers, yards, and warehouses. In case the general warehouse deposit has direct and/or authorized warehouses, they must be subject according to their characteristics to what is established in this document, with the objective of maintaining integrity in the supply chain.
Response: Explanatory Notes: According to the process mapping of merchandise destined for the tax deposit regime, declare if the general warehouse deposit has additional warehouses, warehouses, or distribution centers, and specify if they are direct and/or authorized.
5.3 Delivery and receipt of merchandise. The general warehouse deposit must supervise the receipt and delivery of merchandise in its facility, ensuring at all times its correct identification, registration, and handling according to the procedures established by the warehouse, including the instructions or specifications it receives from clients, where applicable, for its handling and transfer. For the above, the general warehouse deposit must have documented procedures that allow it to safely carry out the delivery and receipt of cargo in distribution centers or warehouses (direct and/or authorized), said procedures must include the receipt, generation of credit letter registration in system, handling according to client specifications, scheduling of warehouse entry tasks, unloading, correct identification and conditioning of merchandise until location in warehouse, documentation generated for the transporter, client, and service personnel. Likewise, the general warehouse deposit must have control mechanisms for the receipt of transport units, in addition to the identification and registration of operators who carry out the delivery or receipt of merchandise in the facilities. Likewise, it must guarantee that the operators who transport the merchandise, during delivery and/or receipt, have all the required documentation to authorize their entry or extraction from the general warehouse deposit and where applicable, the documentary information required for its correct transfer which includes, in an enumerative but not limiting manner, destination, route that it must maintain, contact data, and/or procedure in case of any security incident or inspection by any authority, among others. The cargo preparation areas and the immediate surrounding areas must be inspected regularly to guarantee that these areas remain free of visible pest contamination. During the process of loading and unloading merchandise, the company's security area (supervisor or security guard) must be present to validate that the process is being carried out correctly, mitigate the risk of shipment contamination (prohibited, illicit merchandise, or pests) and register said review (novelty report, records, reports, etc.), as evidence that the high-security seal and/or lock was placed correctly, digital photographs must be taken at the time of loading vehicles. To the extent possible, these images should be sent electronically to the destination or delivery point of the merchandise for verification purposes. Also, the personnel responsible for the shipping and/or receiving area must review the information included in import and/or export documents to identify or recognize suspicious cargo shipments. Likewise, specific training must be provided on the identification of common errors in export shipment documentation, with the objective of preventing these from resulting in security incidents or suspicious merchandise.
Response: Explanatory Notes: Attach the documented procedure in which it indicates the process for the receipt and delivery of merchandise in the facilities, verifying at all times its correct identification, registration, and handling according to the procedures established by the warehouse and ensure to include the following points: a) Method of receipt, unloading, and verification of merchandise. b) Method for the identification of transport operators. c) Generation of credit letter. d) Registration in system (corporate). e) Warehouse or client specifications. f) Identification of merchandise. g) Documentation generated for the transporter, client, and service personnel. h) Merchandise extraction process. i) Documentation delivered to operators. j) How it verifies and guarantees that cargo preparation areas and immediate surrounding areas remain free of visible pest contamination. In case of identifying any type of visible pest, contamination, garbage, insects, grass, weeds, or tall grass, how it reports it and what actions it takes regarding it. k) Indicate how it controls or what security measures it has implemented to mitigate the risk of collusion or complicity between employees, such as the driver and personnel in the dispatch areas (where applicable) warehouse, security guards, etc. l) Indicate if it carries out permanent or random reviews of the luggage of transport operators who enter its facilities to deliver or pick up cargo. In case of identifying any anomaly or having a suspicion, describe the actions it takes regarding it and how it reports to the authority. The merchandise delivery and receipt procedure must include: a) Inspection method at the warehouse access point. b) Designation of personnel responsible for identifying and registering transport media operators upon their arrival. c) Registration of the introduction of merchandise into the general warehouse deposit. d) Exit from the general warehouse deposit.
5.4 Cargo tracking procedure. When the transfer of goods is carried out at the expense of the general warehouse, in accordance with its risk analysis, the integrity and traceability of the goods destined for the fiscal deposit regime must be ensured during their transfer between warehouses, distribution centers, and previously authorized warehouses for this type of goods. The general warehouse must monitor at all times the transfer of the goods (provided that it is its responsibility) to another authorized warehouse of the same warehouse or transferred to a different one, verifying that, for its transfer, the documentation supporting the goods is generated (copy of the import or export declaration for fiscal deposit, as well as with the tax receipt issued by the same general warehouse) and must give the corresponding transfer notice to the authority through electronic transmission to the SAAI, indicating the necessary information (folio of the electronic capacity letter, number of authorization or key of the authorized warehouse to which the goods will be transferred, tariff fraction, etc.), in accordance with what is established in rules 4.5.13. and 4.5.14. If as a result of monitoring and tracking, a real (or concrete) threat to the security of a shipment or means of transport is identified, the general warehouse must alert (as soon as possible) the business partners in the supply chain that may be affected and, where appropriate, the authority as appropriate. Response: Explanatory Notes: Attach the documented procedure to monitor the transfer of goods destined for the fiscal deposit regime to another authorized warehouse of the same warehouse or transferred to a different one, in accordance with what is established in rules 4.5.13. and 4.5.14. This procedure must include, among other aspects according to its operation: a) Indicate the type of system implemented by the units used for the control of goods destined for the fiscal deposit regime and, if applicable, if it is a third-party or subcontracted service, describe the consultation tools available to monitor the goods. b) Identification of predetermined routes and estimated transfer/delivery times, between intermediate points, as well as overnight stay and/or rest (yards, exit customs, customs broker's facilities or customs agency, freight agents, among others). Once the time between the assigned points has been determined, they must have a tracking process (route audit) and the corresponding records. c) In the case of geofences, within their parameters, minimum tolerances allowed for the predetermined transit route must exist or be established. d) There must be systems or procedures with instructions in case of a delay in the route (stoppages, changes or diversions of route, mechanical failures, accidents, etc.). Likewise, drivers must notify (to their supervisor and, if applicable, to the sender or consignee of the goods) any significant delay in the route due to weather, traffic, accidents, mechanical failures, change of route, etc. And on its part, the company must independently verify the cause of said delay. e) Detail if it has communication means for the tracking of the goods. f) Point out the area or person responsible for supervising this process. The procedure must also include that, in case of identifying a real or concrete threat to the security of a shipment or means of transport; how the company informs the business partners of its supply chain that may be affected and, if applicable, the authority as appropriate, about this type of incidents or presumptions.
5.5 Cargo discrepancy report. There must be documented procedures to detect and report missing, surplus, prohibited, or any other discrepancy in goods during delivery and/or receipt of the goods, with the purpose of having information that helps the corresponding investigations by the competent authorities in case of any security incident. Likewise, it must describe the measures and actions to be taken in case of identifying illicit, undeclared, and prohibited goods (in accordance with what is provided for in article 123 of the Law) or those that by their nature put the safety of personnel at risk during the processes of receipt, delivery, transfer, transfer, storage and, if applicable, in accordance with the services offered. Response: Explanatory Notes: Attach the documented procedure to detect and report discrepancies of missing, surplus, prohibited, or any other discrepancy in goods during delivery and/or receipt of the same and ensure that it includes the following points: a) Persons responsible for carrying out the review. b) Documents to be checked. c) Areas to which the information is reported. d) What actions they take in case of detecting any discrepancy.
5.6 Processing of cargo information and documentation. The general warehouse must have documented procedures to ensure that the electronic and/or documentary information used during the receipt, storage, custody, and extraction of goods destined for the fiscal deposit regime, as well as the information received from business associates, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. Likewise, forms and documentation related to import and/or export should be secured to prevent unauthorized use. Response: Explanatory Notes: Describe the procedure for the processing of cargo information and documentation, ensure that you include the following points: a) Detail how it transmits and/or receives information and documentation related to the receipt and delivery of goods in the general warehouse. b) Indicate if it uses a specific computer control system and explain briefly how it works. c) Likewise, detail how it validates that the information provided by the different actors in the supply chain (transporters, customs brokers, shipping lines, railway companies, among others) that converge in the warehouse, is legible, complete, accurate, reported in time, and protected against changes, losses, or introduction of erroneous information. d) Point out how business associates transmit information with the company and how they ensure its protection.
5.7 Inventory management, control of packaging, container, and packaging material. The general warehouse must have documented procedures to carry out automated inventory control in accordance with its authorization to provide fiscal deposit services for goods; likewise, said control must contemplate what refers to fiscal deposit auctions, fiscal deposit donations to the Federal Treasury, return of goods abroad, transfers and transfers, destructions, among others, in accordance with applicable regulations and guarantee that cyclic inventories are carried out on the goods. Packaging, container, and packaging materials, if applicable, must be controlled and supervised to prevent them from being susceptible to manipulation prior to their use. Response: Explanatory Notes: Attach the documented procedure for the management of cargo inventories. This must include, according to its operation among other aspects, the following: a) Mention what type of system it uses for the exchange of information with the authority for inventory purposes. b) Who is its supplier. c) Indicate if it has a contingency plan in case of system failures. d) Mention where the system is physically located and who are the responsible for its operation. e) The frequency with which it carries out the verification of stock (cyclic inventory). Indicate if there is a scheduled calendar to carry them out and if it is documented. f) Indicate what actions it takes in case of surpluses and shortages in inventories. g) Point out the treatment given to the control and handling of packaging, container, and packaging material. h) Treatment of goods when they present deterioration, as well as what is related to their destruction. i) This point is also focused on reducing the risk of introduction or dissemination of pests of quarantine importance to the country through packaging (imports), for which reason, describe how it complies with the provisions indicated by the Secretariat of Environment and Natural Resources (SEMARNAT) and NOM-144 SEMARNAT-2017, in concordance with the International Standard for Phytosanitary Measures No. 15 called Regulation of Wood Packaging Used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations. j) Point out how the fumigation process is to kill, inactivate, sterilize, desiccate, or eliminate pests. What actions does it take in case of requiring quarantine of packaging materials? k) Indicate the area responsible for carrying out this process, as well as the documentation or certificates obtained. The applicant's procedures may include: a) Access restrictions to the warehouse so that only authorized personnel enters. b) Actions taken if irregularities, discrepancies, losses, or thefts are identified. c) Separation of the various types of goods, for example, high value, dangerous.
6.1 Customs obligations. The general warehouse must have documented procedures for the compliance of customs obligations derived from its authorization, in accordance with what is stated in Chapter 4.5., applicable to general warehouses; said procedure must include at least the following: a) Definition of the areas designated within the warehouse, which meet the specifications indicated by the authority to provide the service of storage of goods in fiscal deposit and/or affix labels or seals. b) Process for the request of addition, modification, and/or exclusion of installations from the authorization (of the same premises, warehouse, yard, cold chamber, silo or tank, between two general warehouses simultaneously, etc.) to provide the service of storage of goods in fiscal deposit. c) Permanent and simultaneous registration of entry and exit of goods to the general warehouses (designation of the computer equipment and data transmission equipment so that the respective customs and the administrative units of the AGACE can perform the consultation of the permanent and simultaneous registration in the system that the general warehouse has for this purpose). d) Joint liability. e) Rectification of capacity letter (notice of surpluses and shortages within twenty-four hours following the arrival of the goods through electronic transmission to the SAAI, notice of late arrival, and notice of non-arrival of goods). f) Identification of fiscal deposit goods (adhesive labels). g) Goods not susceptible to fiscal deposit. h) Auction. i) Donation to the Federal Treasury. j) Returns. k) Transfer (in this case, the customs of jurisdiction of the general warehouse in which the goods are located must be modified). l) Transfer. m) Notices corresponding to the authority. n) Destruction or loss of goods. Response: Explanatory Notes: Attach the procedure established to comply with the customs obligations derived from its authorization as a general warehouse, in accordance with what is stated in Chapter 4.5., applicable to general warehouses. Likewise, said procedure must also contemplate the following points: a) Process that goods that are subjects of conservation acts, exhibition, placement of commercial identification signs, packaging, examination, demonstration, and sampling must comply with. b) Reports to the authority within the twenty-day period following the issuance of the capacity letter, the surpluses or shortages of the goods manifested in the declaration with respect to those actually received. c) Compliance with the contributions and compensatory quotas that are incurred by the import and export of goods that they have in fiscal deposit and the obligation to pay them to the authority. d) Communication process with the authority and the client, in case of damage or loss of goods.
6.2 Customs verification. In order to verify the truthfulness of the information declared by the general warehouse before the competent authorities, there must be documented procedures so that the personnel designated by the warehouse periodically verifies that the registered declarations and the information of electronic capacity letters coincide with what is declared in the SAAI Web and, if applicable, report to the customs authority any discrepancy in said information. The general warehouse, likewise, must have a procedure for the filing of declarations for their adequate control. Response: Explanatory Notes: Attach the procedure established to verify that the information registered in the SAAI Web is checked and coincides with the information of the registered declarations, the capacity letters, and other documentation generated by the general warehouse.
7.1 Cargo integrity and use of seals in containers and trailers. The general warehouse must ensure that the cargo transport means owned and/or subcontracted by the warehouse to carry out transfers or transfers of goods destined for the fiscal deposit regime (which may be: maritime, air, national land, cross-border, railway, and/or multimodal, etc.), use seals and/or locks that comply with the ISO 17712 Standard in order to comply with the provisions of the customs authority and guarantee at all times the integrity of the cargo. For this case, the general warehouse must have a documented procedure in which, in accordance with its risk analysis, it supervises the placement of seals and/or locks that comply with the ISO 17712 Standard in the cargo transport means owned and/or subcontracted for transfers or transfers of goods destined for the fiscal deposit regime. In it, it must evidence the controls that allow accrediting that it supervises the portability of seals and/or locks, resulting from entries and exits of the general warehouse. In all cases, it must use the VVTT inspection method to mitigate improper manipulations as follows: a) V- View the seal and lock mechanisms of the container (View). b) V- Verify the seal number (Verify). c) T- Pull the seal to ensure it is correctly placed (Tug). d) T- Twist and turn the seal to ensure it has been closed (Twist and Turn). Likewise, it is necessary to have a documented procedure for the administration of the same, which includes the control, assignment, storage, handling of discrepancies, and destruction of seals and locks (the latter is mandatory whenever seals are broken in its facilities). Regarding the supplier of the seals and/or locks, it must be demonstrated how these comply with the ISO 17712 Standard. In case of such an inspection, drivers must notify and register any anomaly or unusual structural modification found in the means of transport resulting from said review. The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to the business partners involved in the supply chains, and the investigation of the security incident; these must be notified to security personnel, business partners that may be part of the affected supply chain, security specialist, or contact of the Authorized Economic Operator Program. The warehouse management or a security supervisor must carry out periodic and documented audits of the high-security seals and/or locks; these reviews must include the verification of the inventory of seals and/or locks stored and the comparison with the inventory records and shipping documents. Also, the supervisors of the shipping area and/or warehouse managers must periodically verify the seal numbers used in the means of transport and Instruments of International Traffic to corroborate that the information is correct. Response: Explanatory Notes: Attach the documented procedure to supervise the placement and review of high-security seals and/or locks in the cargo transport means owned and/or subcontracted (cargo vehicles, containers, train cars, trailers, and/or semi-trailers) to carry out transfers or transfers of goods destined for the fiscal deposit regime. According to its operation, said procedure must include among other aspects: a) What type of seals and/or locks it uses and how it verifies that they comply with or exceed the ISO 17712 Standard. b) The use of the VVTT inspection method. c) Review and check the documentation containing the number of the original seal and/or lock upon entry to the general warehouses. In case of using the replacement seal and/or lock, said number must be registered within the control of the general warehouse. If altered seals and/or locks are identified, they must be kept to help carry out the investigation of said incident or discrepancy.
d) Review that closing devices, hinges, and pins are attached to the trailer or container and welded or riveted. Additionally, protective plates may be placed on door hinges and/or a seal/adhesive tape placed on at least each side. It is also necessary to verify the correct functioning of handles, latches, and all other locking or closing mechanisms of cargo vehicles to detect manipulations and any inconsistencies before placing any sealing device.
If applicable, attach the documented procedure for the control and handling of seals and/or padlocks. This must include, among other aspects according to your operation:
a) What type of seals and/or padlocks are used in your operations (foreign trade, transit, storage, etc.). b) Indicate who has access and how high-security padlocks and/or seals are safeguarded. The management of seals and/or padlocks must be restricted only to authorized personnel; stored in a secure place, have an inventory, control of their distribution and tracking (record of seals used, as well as the receipt of new seals and/or padlocks). c) Describe how the management of the general bonded warehouse or the security supervisor participates in audits of high-security seals and/or padlocks, the reviews they perform, the records kept, and the actions taken in case discrepancies are identified. Also, how supervisors of the shipping area and/or warehouse managers verify seal numbers used in transport means and International Traffic Instruments to corroborate that the information is correct (this process may also be included within the internal audits referred to in sub-standard 1.3 of this document). d) Indicate how the control and handling of high-security padlocks and/or seals (inventory) are carried out. e) How discrepancies in high-security padlock and/or seal numbers are addressed.
All written procedures must be disseminated and maintained at the operational level so that they are easily accessible to employees responsible for executing the tasks described above, reviewed at least once a year, and updated as necessary.
7.2 Inspection of transport means, containers, train cars, trailers, and semi-trailers. There must be established procedures to verify the physical integrity of the structure of transport means, containers, train cars, trailers, and/or semi-trailers entering and leaving the general bonded warehouse, including the reliability of the locking mechanisms therein, with the aim of identifying natural or hidden compartments, as applicable.
Inspections of transport means or cargo vehicles, containers, trailers, and semi-trailers (land or rail cargo) must be systematic and carried out upon entry and exit from the general bonded warehouse and, if applicable, at the cargo loading point and, if infrastructure allows, before arriving at the customs office for clearance using the VVTT inspection method. A record of these inspections must be kept in an area with controlled access and carried out in a place monitored by alarm, closed-circuit television, and video surveillance systems; said system must cover the entire inspection process.
The documented procedure for inspection must include, enumeratively but not limitatively, the following review points:
Transport Means: Trailers, train cars, semi-trailers, and containers
Bumper;
Tires and rims (tractor and trailer);
Floor (tractor);
Fuel tanks;
Cab interior (bedroom, tool compartment);
Air tanks;
Chassis;
Fifth wheel area;
Drive shafts;
Exhaust pipe;
Engine.
Exterior and interior doors;
Side walls (left and right);
Interior and exterior roofs;
Front wall;
Internal floor;
If applicable, the refrigeration system.
For transport means with an integrated trailer or cargo compartment, the points indicated in the trailers section must be added to the transport means points.
Similarly, before loading transport means, containers, train cars, trailers, and semi-trailers used as International Traffic Instruments, they must undergo agricultural and security inspections to guarantee that their structures have not been modified to hide contraband or have been contaminated with visible agricultural pests, maintain a record, and be backed by a documented procedure. If visible pest contamination is found during the inspection or transport of goods subject to foreign trade, it must be cleaned (washed, vacuumed, etc.) to eliminate said contamination.
Response: Explanatory Notes: Attach the documented procedure to carry out the systematic security and agricultural inspection of transport means or cargo vehicles, containers, train cars, trailers, and/or semi-trailers during entry and exit from the general bonded warehouse and/or at the cargo loading point. This must include, among other aspects according to your operation:
a) Those responsible for carrying out the inspection. b) Define the location(s) where the inspection takes place and indicate how monitoring is performed by alarm, closed-circuit television, and video surveillance systems.
c) The review points for transport means, trailers, semi-trailers, containers, rail transport, and/or multimodal transport, both for security and quality and agricultural inspections whose purpose is to search for visible pests in accordance with official regulations. d) Attach the established format for the inspection of transport means or cargo vehicles, containers, train cars, trailers, and/or semi-trailers. If another type of cargo vehicle enters your facility for the transport of goods (vans, pickups, 3.5-ton trucks, tankers, etc.), your procedure and inspection format must include the process and review point.
Likewise, the security and agricultural inspection format must include the following information: a) Date of inspection; b) Time of inspection; c) Vehicle license plates (tractor and trailer); d) Container/trailer number; e) Specific areas of the cargo vehicles that were inspected, and f) Name and signature of the employee performing the inspection and the supervisor.
Security and agricultural inspection formats may be signed by the supervisor to corroborate their information and become part of the import and export documentation.
Documentation must be preserved for one year for investigation in case of any security incident, as well as to demonstrate continuous compliance with these inspection requirements.
Additionally, and based on risk analysis, the warehouse should perform periodic random reviews of cargo vehicles after transport personnel have performed security inspections to verify that they were carried out correctly, counteract internal conspiracies, and prevent security incidents.
Reviews must be carried out randomly, without prior notice, so that they do not become predictable, in addition to being carried out in different locations where the transport means may be susceptible to contamination.
Indicate whether the repair or maintenance of transport units, containers, or trailers is performed in the same facilities or carried out with an external provider.
7.3 Custody of vehicles, transport means, containers, train cars, trailers, and semi-trailers. In the event that transport means or cargo vehicles, containers, trailers, and semi-trailers (land or rail cargo) destined to transport goods subject to the fiscal deposit regime are empty and, if applicable, are stored in parking areas, they must be secured with a padlock and/or indicative seal, or in a secure area protected and/or monitored by alarm, closed-circuit television, and video surveillance systems.
When it is necessary to store any container, trailer, and/or semi-trailer loaded with goods subject to the fiscal deposit regime, it must be located in a secure area with perimeter barriers and monitored by alarm, closed-circuit television, and video surveillance systems to prevent unauthorized access and manipulation of the goods; therefore, it must be closed with a high-security seal and/or padlock in accordance with ISO 17712 Standard.
Response: Explanatory Notes: Indicate if the general bonded warehouse stores containers, trailers, and/or semi-trailers for subsequent clearance, or if applicable, those that are empty, and how it maintains their integrity within its facilities.
In case of using padlocks and/or seals for empty containers, trailers, and semi-trailers, indicate what type is used.
In case of using any container, trailer, and/or semi-trailer as a warehouse for raw material and/or any other type of goods, indicate how the integrity and security of the same are maintained.
Additionally, there must be continuous training programs for administrative and operational staff in which security policies in the warehouse's supply chain, consequences, and actions to consider in case of any breach or security incident are disseminated.
8.1 Employment background verification. The general bonded warehouse must have documented procedures to investigate and verify the information stated in the curriculum, criminal records (if local legislation and the warehouse's policies allow), and applications of candidates with potential for employment, in accordance with local legislation, either independently or through an external company.
Similarly, for positions that require it due to their sensitivity and affect the security of shipments with goods subject to the fiscal deposit regime, in accordance with the previously conducted risk analysis, stricter requirements for hiring must be requested, which must be carried out periodically (at least once a year). Regarding personnel already working in the company, periodic investigations must be conducted based on the activities and/or sensitivity of the employee's position.
All information regarding personnel must be kept in personal files, which must have restricted access.
Response: Explanatory Notes: Describe the documented procedure for personnel hiring, and ensure you include the following: a) Requirements and documentation demanded. b) Tests and exams requested.
Indicate the areas and/or critical positions identified as risk according to your analysis and indicate the following: a) Indicate what the additional requirements are for specific areas and/or job positions, such as criminal records (if company legislation and policies allow), non-criminal record certificate, socioeconomic studies, clinical studies, toxicological (drug use). If applicable, indicate the positions or work areas where they are required and with what frequency they are carried out. b) Indicate if, prior to hiring, the candidate must sign a confidentiality agreement or a similar document.
In case of hiring a service agency for personnel hiring, indicate if it has documented procedures for personnel hiring and how it ensures compliance with them. Briefly explain what they consist of.
Procedures for personnel hiring and contractors must include: a) Thorough investigations of the work and personal backgrounds of new employees. b) Confidentiality and liability clauses in employee contracts. c) Specific requirements for critical positions. d) If applicable, the periodic update of the socioeconomic and physical/medical study of employees working in critical and/or sensitive areas. e) Hiring process and requirements requested for temporary employees and contractors. f) The company may consider the results of background checks of candidates, as permitted by current legislation, to make hiring decisions. Background checks are not limited to identity and criminal record verification. In higher-risk areas, deeper investigations may be justified.
8.2 Personnel termination procedure. There must be documented procedures for personnel termination, which include the delivery of identification and any other item provided to perform their functions (keys, uniforms, badges and/or credentials, computer equipment, passwords, tools, etc.). Likewise, this procedure must include termination in computer and access systems, among others that may exist.
Response: Explanatory Notes: Describe the procedure for personnel termination, and ensure you include the following: a) Who is responsible for carrying out and following up on this procedure. b) How the delivery of identification, uniforms, keys, and other equipment is performed and confirmed. c) Indicate the control, record, and/or format in which the delivery of material and termination in computer systems (if applicable) is identified and ensured. d) Specify the type of records of personnel who ended their employment relationship with the general bonded warehouse, so that in case it was for security reasons, their service providers and/or business associates are warned.
8.3 Personnel administration. The general bonded warehouse must maintain an updated system, control, or database of active employees; likewise, it must perform and maintain updated records of affiliation to social security institutions and other legal labor records.
In the event that the general bonded warehouse has personnel hired by its business partners and working within the facilities, it must ensure that they comply with the requirements established for the rest of its employees.
Response: Explanatory Notes: Indicate if the general bonded warehouse has an updated system, control, or database, both for personnel employed directly and that hired through a service provider company, and ensure it includes, enumeratively but not limitatively, the following points: a) Full name. b) Updated photograph at least every five years. c) Personal data (age, name, date of birth, phone number, address, CURP, social security number, blood type, allergies, etc.). d) Affiliation.
e) Work background. f) Illnesses. g) Medical exams. h) Training. i) Psychometric tests. j) Toxicological tests. k) Results of periodic evaluations. l) Observations.
This personnel must be hired in accordance with current labor laws and regulations.
9.1 Document classification and handling. There must be written procedures to classify documents according to their sensitivity and/or importance. Sensitive and important documentation must be stored in a secure area that only allows access to authorized personnel. The useful life of the documentation must be identified, and procedures for its destruction must be established.
The general bonded warehouse must conduct regular reviews to verify access to information and ensure that it is not used improperly.
Response: Explanatory Notes: Attach the documented procedure for the registration, control, and storage of printed and electronic documentation (document classification and filing), which must include: a) Control register for delivery, loan, and other documents. b) Restricted access to the archive area. c) Storage and classification policies. d) An updated security plan describing the measures in force regarding the protection of documents against unauthorized access, as well as against deliberate destruction or loss of the same. e) In the case of electronic or digital information, it must adhere to the security criteria of sub-standard 9.2 Information Technology Security.
9.2 Information Technology Security. To protect Information Technology systems against common cybersecurity threats, the general bonded warehouse must have sufficient protection that promotes security in Information Technology infrastructure (software and hardware) against malware (viruses, spyware, worms, trojans, etc.), baiting, phishing, and internal/external intrusions (firewalls) in the companies' computer systems. Likewise, the general bonded warehouse must ensure that its security software is active and receives periodic updates.
In the case of automated systems and computer equipment, individual accounts requiring periodic password changes must be used. In order to protect the confidentiality, integrity, and availability of information, the warehouse must have established Information Technology policies, procedures, and standards, which must be communicated through a training program for all employees handling computer equipment and systems, including topics to prevent attacks through social engineering and all other threats to which they are exposed (malware, baiting, phishing, etc.). Warehouses that allow their employees to connect remotely to a network must employ secure technologies, such as virtual private networks (VPN), to allow employees to access the warehouse intranet securely when outside the office, as well as procedures designed to prevent unauthorized remote user access.
Therefore, there must be written procedures and infrastructure to protect the general bonded warehouse against loss, theft, leakage, hacking, and/or ransomware of information; this includes the procedure for the recovery (or replacement) of Information Technology systems and/or data, as well as a system or software established to identify the abuse of Information Technology systems, detect inappropriate access and/or improper manipulation or alteration of commercial and business data, as well as a written procedure for the application of appropriate disciplinary measures to all offenders. Access to Information Technology systems must be protected against infiltration through the use of secure passwords, which include phrases or other forms of authentication. Users of said Information Technology systems must safeguard and not share their access keys or passwords. All Information Technology infrastructure must be physically protected against unauthorized access.
If a data leak or other unexpected event occurs resulting in the loss of data and/or equipment, the procedures must include the recovery or replacement of Information Technology systems and/or data.
Response: Explanatory Notes: Attach the procedure for the recovery (or replacement) of Information Technology systems and/or data, which includes how it backs up and ensures the security of its information, in addition to protecting it from possible losses. Ensure you include the following points: a) Indicate the frequency with which information backups are carried out. b) Who has access to them and who authorizes the recovery of information. c) Indicate what type of tests are performed and how often, to verify the security of the network, systems, and infrastructure. d) Mention if, to perform this type of tests or vulnerability scans, it is done through software, a third party, or provider, and if so, indicate the name or corporate name. e) In case vulnerabilities are found, describe the corrective actions that must be implemented.
f) Indicate whether you share information about cybersecurity threats with your business partners participating within your supply chain (for example: communications, bulletins, emails, etc.). g) Systems must be protected by passwords and must be changed frequently; therefore, indicate the procedure for changing them. h) State whether there are information security policies for their protection. i) There must be a system or software to detect and identify abuse, intrusion, or unauthorized access by persons to your systems and/or Information Technology data (any system used by the company), as well as the abuse of policies and procedures established by the general warehouse, including improper access to internal systems, external websites, and the manipulation or alteration of commercial data by employees or contractors. j) All offenders must be subject to the application of disciplinary measures; therefore, indicate the corrective policies and/or sanctions in case of detection of any violation of Information Technology systems and security policies.
Information Technology and cybersecurity policies and procedures must be reviewed annually and updated resulting from an attack or according to situations that may put the company's systems at risk.
Describe the security measures you use to allow employees to connect remotely to a network (VPN), to allow employees to access the general warehouse intranet remotely when they are outside the office.
In the event that you allow employees to use personal devices to perform warehouse work, such devices must comply with the company's cybersecurity policies and procedures, security updates must be periodic, and they must have a method to securely access the company network.
k) State whether business partners have access to the general warehouse's computer systems. If so, indicate which programs and how they ensure access control to them. l) Indicate if the computer equipment has an uninterruptible power supply system that allows for business continuity.
Procedures regarding the backup of the general warehouse's information must include: a) How and for how long data is stored (data should be backed up once a week or as appropriate). b) Business continuity plan in case of incident and how to recover information. c) Frequency and location of backup copies and archived information. d) Whether backup copies are stored in sites alternative to the facilities where the Data Processing Center is located. e) Tests of the validity of data recovery from backup copies.
Procedures regarding the protection of the general warehouse's information must also include at a minimum the following: a) An updated and documented policy for the protection of computer systems against unauthorized access and deliberate destruction or loss of information. All sensitive and confidential data must be stored in an encrypted or encoded format. b) Detail if you operate with multiple systems (locations/sites) and how such systems are controlled. c) Who is responsible for the protection of the computer system (responsibility should not be limited to one person but to several so that each can control the actions of the others). d) Each user's access must be assigned through individual accounts and restricted according to the job description or assigned tasks. Therefore, describe how access authorizations and levels of access to computer systems are granted (access to sensitive information must be limited to personnel authorized to make modifications and use the information). Authorized access must be monitored by the area responsible for granting it, to verify or, if applicable, report that access to confidential systems is based on job requirements. e) Indicate the elements or format that passwords must have for access to Information Technology systems and computer equipment, frequency of changes, if there are other authentication methods, and who or what area provides those passwords. f) Indicate the name of the firewall and antivirus used (include licensing information), evidencing that this security software is active and receives periodic updates.
Therefore, cybersecurity policies and procedures should include measures to prevent the use of counterfeit products or those with incorrect licenses (software and hardware).
All computer equipment, electronic media (hard drives, cell phones, etc.), and Information Technology hardware containing confidential information related to the import and export process must be accounted for through periodic inventories and have such evidence. When these technological equipments must be disposed of, there must be a documented procedure that includes how they must be formatted, disinfected, or destroyed appropriately to avoid information leakage. g) In the event of employee termination, access to computer equipment, telecommunications, and the network must be eliminated at the moment of the employee's separation; this includes email accounts, system access accounts, software, programs, etc. h) Measures planned to handle incidents in case the system is compromised.
Administrative and operational employees must know the established procedures of the general warehouse to identify a risk situation and know how to report it. Specific training must be provided to employees who, due to their functions, are in direct contact with computer systems, goods, and/or transport means, as well as to employees who are in critical and/or sensitive areas determined under their risk analysis (security areas, shipments and receipts, if applicable, as well as those who receive and open mail and packages, among others).
10.1 Training and awareness on threats. The general warehouse must have a training and awareness program on supply chain security policies directed to all its employees (operational and administrative) and, additionally, make available informational material regarding the procedures established in the company to consider a situation that threatens its security and know how to report it.
Likewise, specific training must be offered according to their functions to help employees maintain the integrity of the goods destined for the tax deposit regime during their receipt, handling, storage, guard, custody, and exit from the warehouse, perform the review of transport means, containers, train cars, trailers, and/or semi-trailers for agricultural and security purposes, receipt and review of mail and packages, prevention of operations with illicit funds (money laundering, terrorism financing, etc.), how to recognize and how to report internal conspiracies, protect access controls, as well as training regarding smuggling, cargo theft, placement of high-security seals and locks (VVTT inspection method), prevention of visible pest contamination, etc.
These topics must be established as part of new employee onboarding and maintain periodic update programs. Update training must be carried out periodically, after a security incident, and when there are changes in the general warehouse procedures.
In addition to security training programs, an awareness program on alcohol and drug consumption must be included. Also, disseminate and train personnel on the general warehouse's cybersecurity policies, procedures, and standards (theft, leakage, hacking, and/or information kidnapping), including access to computer equipment and systems via passwords or phrases. Personnel who operate and administer security technology systems must receive training related to their operation and maintenance, including self-training through operational manuals and other methods. These topics must be established as part of new employee onboarding and maintain periodic update programs.
Training programs must encourage active employee participation in security controls and mechanisms, as well as maintain records of all training efforts provided by the general warehouse and the list of those who participated in them (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date of the training, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all training objectives.
Response: Explanatory Notes: You must have a training program on security and prevention of security incidents in the supply chain for all employees working for the general warehouse (administrative, operational, direct, and indirect). Briefly explain what the training program consists of, and ensure you include the following: a) Brief description of the topics taught in the program. b) When they are taught (onboarding, specific periods, resulting from audits, security incidents, etc.). c) Frequency of training, as well as updates and reinforcement. d) Indicate how participation in supply chain security training is documented (videos, photographs, minutes, attendance lists, intranet or other system, didactic material, PowerPoint presentations, brochures, etc.). Training records must include the date, the names of the attendees, the topics taught, in addition to having measures to verify that the training provided met all the objectives of the same. e) Explain how employee participation in supply chain security issues is encouraged.
Training to perform the review of cargo vehicles, containers, trailers, and/or semi-trailers for agricultural and security purposes must include the following topics: a) Signs of hidden compartments; b) Smuggling hidden in natural compartments; c) Signs of pest contamination; and d) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit. e) Training on agricultural reviews must cover pest prevention measures, regulatory requirements applicable to wooden packaging materials in accordance with International Standard for Phytosanitary Measures No. 15, named Regulation of wooden packaging used in International Trade, which emanate from the Food and Agriculture Organization of the United Nations, and the identification of infested wood.
10.2 Awareness for transport medium operators. The general warehouse must make known to the operators of the transport means used for the transfer and transshipment of goods destined for the tax deposit regime, the security policies regarding agricultural and transport medium security inspection procedures, loading and unloading, handling of security incidents, replacement of seals and/or locks in case of inspection by other authorities, among others, that are implemented. Operators and personnel who perform agricultural and security inspections of transport means must be trained to inspect cargo vehicles for such purposes.
In the event that the transport service is provided by your business partner, you must ensure that the operators and/or drivers who transport the goods know all the security policies and procedures established by the general warehouse.
Response: Explanatory Notes: Describe the dissemination program on supply chain security focused on transport medium operators and ensure you include the following: a) Indicate how this dissemination is carried out. b) State the topics covered. c) In case of using the services of a business partner for the transfer and transshipment of your goods, indicate how operators are informed of the general warehouse's security policies and procedures. d) Indicate how participation in supply chain security training of transport medium operators is documented (videos, attendance lists, brochures, etc.).
The topics that must include, by way of example and not limitation, are: a) Access and security policies at the facilities. b) Delivery and receipt of goods (including suspicious cargo shipments). c) Confidentiality of cargo information. d) Transfer and transshipment instructions. e) Accident and emergency reports. f) Instructions for the placement of high-security locks and/or seals in case of inspection by other authorities in transit (placement of a new one, review after an authorized stop, etc.). g) Installation and testing of security alarms and unit tracking, when applicable. h) Identification of authorized formats and documents to be used. i) Signs of hidden compartments. j) Smuggling hidden in natural compartments. k) Signs of pest contamination. l) Procedures to follow if something is found during a transport medium inspection or if a security incident occurs during transit.
In the case where the general warehouse identifies that any foreign trade shipment is involved in a situation that puts the supply chain security at risk, due to suspicion of a business partner or person, it must inform the competent authority, business partners who may be part of the affected supply chain, the security specialist or contact of the Authorized Economic Operator Program, as well as the competent authority, and, if possible, before the border crossing, exit, or customs clearance (import and export). The procedures must include the steps to follow if it is discovered that a seal is altered, manipulated, or there is an incorrect seal number in the documentation, the communication protocols to the business partners involved in the supply chain, and the investigation of the incident. All the aforementioned procedures must be reviewed periodically or at least once a year to ensure that contact information and action protocols are correct.
11.1 Reporting of anomalies and/or suspicious activities. In the event of detection of anomalies and/or suspicious activities related to supply chain security and in accordance with your logistics processes (related to access control, delivery, receipt, and storage of goods, security inspections of cargo vehicles and transport operators, etc.), they must be notified to security personnel, business partners who may be part of the affected supply chain, the security specialist or contact of the Authorized Economic Operator Program, and other competent authorities, keeping a record of said anomalies and/or suspicious activities.
Response: Explanatory Notes: Describe the procedure to denounce or report anomalies and/or suspicious activities, likewise, indicate the mechanisms to anonymously inform about problems related to security, ensure you include the following: a) Who is responsible for reporting incidents. b) Detail how you determine and identify with which authority to communicate in different scenarios or presumption of suspicious activities. c) State the type of record for the reporting of anomalies and/or suspicious activities and briefly describe what it consists of.
11.2 Investigation and analysis. The general warehouse must have written procedures to denounce or report anomalies and/or suspicious activities, as well as the analysis and investigation of security incidents in the supply chain and to determine their cause, in addition to corrective actions to prevent them from happening again, which must be implemented as soon as possible. The information derived from this investigation must be documented, integrated into a file (physical and/or electronic), and be available at all times for authorities that require it.
This information and generated documentation must be included in a file for the purpose of allowing the identification of each of the processes through which that operation went until the point where the security incident was detected, allowing recognition of what the vulnerability of the supply chain was.
Response: Explanatory Notes: Describe the documented procedure to initiate an investigation in case of any security incident occurring, and ensure you include the following: a) Responsible for carrying out the investigation. b) Documentation that integrates the investigation file.
The documents to include in the file derived from the security incident investigation, by way of example and not limitation, may be: a) Cargo information. b) Information of the transport company and the operator and/or driver, entry and exit records to the general warehouse. c) Inspection formats of the transport medium, container, train car, trailer, and/or semi-trailer. d) Records of delivery and receipt of goods destined for the tax deposit regime. e) Videos from alarm systems, closed-circuit television, and video surveillance. f) Documentation generated for the transport company. g) Documentation generated by and for business partners and customs authorities. h) In case, the tracking and monitoring report of the unit (GPS tracking).
...
Jue ve s3 d e ag osto d e 20 23 DIA RIO O F ICIA L 397 F3. Application for Registration in the Enterprise Certification Scheme. Mark with an X the type of application it is: IVA and IEPS Modality Category A Category AA Category AAA Pre-operational period Commercializer and importer Modality Authorized Economic Operator Modality Category Import and/or Export Category Holding Company Category Aircraft Category SECIIT Category Textile Category Strategic Fiscalized Facility Category Logistics Outsourcing Category Certified Business Partner Category Land Self-Transporter Category Customs Broker Category Rail Transport Category Industrial Park Category Fiscalized Facility Category Mail and Packages Category General Warehouse
IVA AND IEPS MODALITY In the case of the IVA and IEPS modality, select the customs regime. (Mark with an "X" in the applicable boxes). Temporary import for elaboration, transformation, or repair in maquila or export programs (IMMEX). Tax deposit to undergo the assembly and manufacturing process of vehicles for terminal automotive industry companies. Elaboration, transformation, or repair in fiscalized facility. Strategic fiscalized facility.
GROUP COMPANIES Companies that are part of a group, for the purposes of rule 7.1.7. Indicate the name of the companies that are part of the group. (Add as many boxes as necessary). Name RFC
398 OFFICIAL GAZETTE Thursday, August 3, 2023
To prove that it is part of a group, it must attach a diagram of the shareholding and corporate structure, as well as copies of the public deeds, in which the shareholding participation of the companies that are part of the group is stated.
Regarding the companies mentioned in rule 7.1.2., Section B, and 7.1.4., first paragraph, fraction II, they may prove the seniority requirement through one of the companies in the group; they must attach a statement in which they assume joint and several liability referred to in fraction VIII of article 26 of the CFF, for the tax credits that may arise; as well as exhibit a copy of the power of attorney with which the legal representative of the company assuming the joint and several liability proves their personality.
Indicate, if applicable, the type of information that the applicant proves, through one of the companies that are part of the same group: Employees. Infrastructure. Amount of investment (Investment in national territory). Seniority (only for companies mentioned in rule 7.1.2., Section B and 7.1.4., first paragraph, fraction II).
LODGING COMPANIES Companies that have operated during the last 3 fiscal years, for the purposes of rule 7.1.8.
Indicate if you have operated during the last 3 fiscal years in terms of article 183 of the Income Tax Law, as a foreign company under another company with an IMMEX Program in the lodging modality. YES NO
It must attach a copy of the contract celebrated for a minimum of three years with the company that has the IMMEX program under the lodging modality, a declaration, under oath, signed by the legal representative of the company that has the IMMEX program under the lodging modality, regarding the temporality in which the applicant operated as a foreign company under its IMMEX program in lodging modality, likewise exhibit a copy of the power of attorney with which the legal representative of the company with the IMMEX program under the lodging modality proves their personality.
Indicate the name of the company that has the maquila program under the lodging modality with which you have operated for the last three years. Name RFC IMMEX Program
Indicate, if applicable, the type of information that the applicant proves through the company with the IMMEX Program in the lodging modality: Employees. Infrastructure. Amount of investment (Investment in national territory).
Indicate if the company with the maquila program, under the lodging modality, with which you have operated, has the Registration in the Enterprise Certification Scheme, IVA and IEPS modality, Category AAA and is not suspended or subject to the start of a cancellation procedure. YES NO
Thursday, August 3, 2023 OFFICIAL GAZETTE 399
1.1 Predominant economic activity. 1.2. Productive sector. 1.3. Address for hearing and receiving notifications. Street Number and/or exterior letter Number and/or interior letter Neighborhood Postal Code Municipality/Delegation Federal Entity Telephone (with area code) Email
Person authorized to hear and receive notifications. Paternal surname Maternal surname Name(s) RFC including the homoclave Telephone (with area code) Email
Persons authorized as operational liaison with the AGACE. The applicant is required to designate a contact who will be the liaison with the authority, as well as the designation of a substitute. 3.1. Person authorized as operational liaison. Paternal surname Maternal surname Name(s) RFC including the homoclave City and State of residence Position or Job Title Telephone (with area code) Email 3.2. Person authorized as operational liaison (Substitute). Paternal surname Maternal surname Name(s) RFC including the homoclave City and State of residence Position or Job Title Telephone (with area code) Email
Attach a copy of the documentation that proves the labor relationship of the persons indicated as operational liaisons with the applicant company.
400 OFFICIAL GAZETTE Thursday, August 3, 2023
4.3. Present certificates of the total personnel registered with the IMSS, of the SUA, and the documentary support of the payment of the employer-employee contributions, of the last bimester prior to the date of submission of the application, as well as comply with the obligation to withhold and pay the ISR of the workers. Attach from all employer registrations, the certificates of the total personnel registered with the IMSS of the last bimester prior to the date of submission of the application, as well as being up to date in the fulfillment of your obligations to withhold and pay the ISR of the workers. Attach the documentary support of the payment of employer-employee contributions of the last bimester prior to the application, which must be consistent with the SUA presented. Prove that you comply with the obligation to issue payroll CFDIs to your workers, in accordance with articles 29 and 29-A of the CFF, article 99 of the Income Tax Law, and rules 2.7.1.8. and 2.7.5.1. of the RMF.
4.4. Indicate if you are on the list of companies published by the SAT in terms of article 69 of the CFF, with the exception of what is provided in fraction VI of said article. YES NO Likewise indicate if you are on the list of companies published by the SAT in terms of article 69-B, fourth paragraph of the CFF. YES NO
4.5. Indicate if your digital seal certificates are valid. YES NO If affirmative, indicate if any of the circumstances provided for in article 17-H Bis of the CFF were infringed during the last twelve months. YES NO
4.6. Indicate all the addresses registered with the RFC of the legal entity applicant and indicate those in which activities related to your productive process and/or the provision of services are developed (Add the necessary rows according to the number of facilities). Type of installation Federal Entity Municipality or Delegation Neighborhood, street and number Postal code Registration with SE/SAT Performs CE Operations
Of the addresses declared in the table above, indicate in which one(s) the production of your main product or service related to the customs regime in which you request your certification takes place, in terms of value or volume of your production. Attach documentation according to applicable legislation that supports the ownership, use or temporary enjoyment of the property or properties where the productive processes or the provision of services take place, as appropriate, in which a mandatory term of at least one year of validity is established, and that leaves you a validity of at least eight months from the date of submission of the application.
4.7. Indicate if you have updated your contact means for the purposes of the tax mailbox in terms of the penultimate paragraph of article 17-K of the CFF. YES NO
4.8. Indicate if you are suspended in the Importers Register or in the Importers Register of Specific Sectors or Sectoral Exporters Register. YES NO
4.9. Report the name and address of clients and suppliers abroad. Attach a file containing the name and address of your clients and suppliers abroad directly or indirectly linked with the customs regime with which the registration is requested, with which you carried out foreign trade operations during the last twelve months.
4.10. Report the name and RFC of your suppliers of inputs acquired in national territory, linked to the process under the regime for which you request registration, of the last six months. Attach a file containing the name and RFC of your suppliers of inputs acquired in national territory, linked to the process under the regime for which you request registration, of the last six months.
Thursday, August 3, 2023 OFFICIAL GAZETTE 401
4.11. Have the legal use or enjoyment of the property or properties where the productive processes or the provision of the service in question take place. Indicate the address of the property from which you intend to prove ownership, legal use or temporary enjoyment. Attach documentation according to applicable legislation that supports the ownership, legal use or enjoyment of the property or properties where the productive processes or the provision of services take place, as appropriate, in which a mandatory term of at least one year of validity is established, and that leaves you a validity of at least eight months from the date of submission of the application.
4.12. Indicate if the SAT has filed a criminal complaint or denunciation against the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration of the applicant company or declaration of prejudice, as applicable, during the last three years prior to the submission of the application. YES NO
4.13. Indicate if you have an inventory control system, for the registration of your foreign trade operations in accordance with article 59, fraction I of the Law. YES NO Indicate, if you have an inventory control system in accordance with the provisions provided for in Annex 24. YES NO You must attach a file with the report of balances of temporary import merchandise or merchandise subject to foreign trade operations, of a period of one month, which is within the three months prior to the submission of the application. In any case, indicate the following information: Name of the system or data for its identification: Place of residence: (Address(es) in Mexico with access to all its functions of the system)
4.14. Indicate if you keep accounting in electronic media in accordance with article 28, fraction III, of the CFF and rule 2.8.1.5. of the RMF. YES NO
4.15. Indicate if you enter your accounting information monthly through the SAT portal, in accordance with article 28, fraction IV, of the CFF and rule 2.8.1.6. of the RMF. YES NO
4.16. Indicate if the partners, shareholders, as applicable, legal representative with authority for acts of dominion and members of the administration in accordance with the constitution of the applicant company, are up to date in the fulfillment of their tax obligations. YES NO List the partners, shareholders, as applicable, legal representative with authority for acts of dominion and members of the administration in accordance with the constitution of the applicant company, whether they are obliged or not to pay taxes in Mexico: RFC Full Name In their capacity as Nationality Obligated to Pay Taxes in Mexico (YES/NO)
4.17. Declare if your partners or shareholders, and members of the administration, are not linked to any company to which its Registration in the Enterprise Certification Scheme has been cancelled, in accordance with fractions V, VI and VII of Section A; II and III of Section B of rule 7.2.4.; and/or VI, VII and XI of rule 7.2.5. YES NO
402 OFFICIAL GAZETTE Thursday, August 3, 2023
4.18. Indicate if you have made the payment of the corresponding right for the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application. YES NO Indicate the date on which you make the payment, the amount, bank operation number and payment key. $ . Payment date (dd/mm/yy) Amount in national currency Bank Operation Number Payment Key
5.2. Prove the investment in national territory, according to what is stated in the Instruction Manual. Type of Investment General Description Value in national currency Real estate Movable assets
5.3. Indicate if you previously had the Certification in IVA and IEPS matters, the Registration in the Enterprise Certification Scheme under the IVA and IEPS modality or Guarantee of the fiscal interest of IVA and IEPS. YES NO
5.4. If affirmative, indicate if you are up to date in the fulfillment of the obligations related to Annex 30 on said registration. YES NO
5.5. Indicate if your suppliers are on the list of companies published by the SAT, in terms of article 69-B, fourth paragraph of the CFF. YES NO
Indicate if you have carried out operations under your IMMEX program. YES NO
6.2. Indicate if at the time of your application you have the necessary infrastructure to carry out the operation of the IMMEX Program, the industrial or service process in accordance with the modality of your Program. YES NO You must attach photographic evidence of your production plant, as well as of your production process.
Thursday, August 3, 2023 OFFICIAL GAZETTE 403
6.3. Indicate if during the last twelve months you have temporarily imported merchandise and that, at least 60% of the temporary imports of inputs carried out during the same period were transformed and returned, returned in their same state, transferred, destroyed, or a service was provided to them. YES NO Capture the total customs value in national currency of your temporary imports of inputs of the required period according to the previous paragraph: (Capture a value) (A) Concept (declare only those that apply) (B) Commercial value of the concept indicated in Column A (national currency) (C) Customs Value of the temporarily imported inputs included in the concept of column A (D) Percentage that represents with respect to the total of temporary imports of direct materials and inputs. Returns Virtual transfers of merchandise Waste Certificates of Transfer of Merchandise (CTM) Total
In case of having declared that you carry out Certificates of Transfer of Merchandise (CTM), attach a file with the names and addresses of the companies to which you transferred merchandise through Certificates of Transfer of Merchandise (CTM), as well as the amounts in national currency and, if applicable, two Certificates of Transfer of Merchandise (CTM).
NOTE: (Companies with recent acquisition of the IMMEX program). Companies that have obtained their IMMEX Program for the first time before the SE and that have been operating for less than one year, may comply with the general requirement stated in rules 7.1.1., fraction III and 7.1.2., first paragraph, fraction II with the document that supports the hiring of employees and will not be subject to the requirements of rule 7.1.1., fractions X and XI, nor to that stated in rule 7.1.2., Section A, fraction III, however, they must prove the issuance of the CFDIs of payroll issued by the applicant to the hired workers.
6.4. Description of activities related to productive processes or provision of services according to the program modality: Attach document that describes in detail the activities related to productive processes or provision of services according to the program modality, describing from the arrival of the merchandise, its storage, its production process, and return, according to the Instruction Manual.
6.5. Continuity of the export project: Attach maquila contract, sales contract, purchase order or services, or firm orders in force, that prove the continuity of the export project.
NOTE: They cannot submit the registration application in the enterprise certification scheme if they have operated for less than twelve months prior to the submission of said application, except those that prove to be part of a group in accordance with rule 7.1.7. For companies that are part of a group, they must present a statement in which one of the companies that make up the group, has been operating for more than twelve months under the IMMEX Program, assumes the joint and several liability referred to in fraction VIII of article 26 of the CFF, for the tax credits that may arise; as well as exhibit a copy of the power of attorney with which the legal representative of the company assuming the joint and several liability proves their personality.
404 OFFICIAL GAZETTE Thursday, August 3, 2023
8.2. Indicate if at the time of submission of your application you are subject to a cancellation process of the authorization to operate the fiscal deposit regime to undergo the assembly and manufacturing process of vehicles, for terminal automotive industry companies. YES NO
8.3. Indicate if at the time of your application you have the necessary infrastructure to carry out the operation of your regime. YES NO
8.4. Description of activities related to productive processes or provision of services according to your regime: Attach document that describes in detail the activities related to productive processes or provision of services according to the customs regime, describing from the arrival of the merchandise, its storage, its production process and return, according to the Instruction Manual.
8.5. Continuity of the export project: Attach maquila contract, sales contract, purchase order or services, or firm orders in force, that prove the continuity of the export project.
9.2. Indicate if you are subject to a cancellation process of the authorization to operate the regime of elaboration, transformation or repair in Supervised Facility and/or Strategic Supervised Facility. YES NO
9.3. Indicate if at the time of your application you have the necessary infrastructure to carry out the operation of your regime. YES NO
9.4. Description of activities related to productive processes or provision of services according to your regime: Attach document that describes in detail the activities related to productive processes or provision of services according to the customs regime, describing from the arrival of the merchandise, its storage, its production process and return, according to the Instruction Manual.
9.5. Continuity of the export project: Attach maquila contract, sales contract, purchase order or services, or firm orders in force, that prove the continuity of the export project.
10.1. Select and fill in at least one of the following options: That during the last four years or more they have carried out operations under the regime for which they are requesting the IVA and IEPS modality. Start date of operations under the customs regime in which they request the IVA and IEPS modality dd/mm/yyyy
That during the last twelve months on average they had more than one thousand employees registered with the IMSS. Average number of employees registered with the IMSS Number of employees
That the value of their machinery and equipment is greater than $50,000,000.00 in national currency. Total value of machinery and equipment $
10.2. Declare whether any credit has been determined against them by the SAT in the twelve months prior to the date of submission of the application. YES NO In the affirmative case, prove that they are authorized to pay in installments in a deferred manner the omitted contributions and their accessories, or that payment in installments has been authorized, or that they have made the payment thereof.
10.3. Declare whether a resolution of improcedence of the requested IVA refunds has been issued to them in the last six months, counted from the date of submission of the corresponding certification application, whose amount does not represent more than 20% of the total authorized refunds and/or that the denied amount does not exceed $5,000,000.00 in national currency individually or collectively. YES NO In the affirmative case, indicate the percentage and amount that represent, of the total authorized refund requests, those in which the authority has issued a resolution of improcedence. Percentage: % Amount: $
11.1. Select and fill in at least one of the following options: That during the last seven years or more they have carried out operations under the regime for which they are requesting the IVA and IEPS modality. Start date of operations under the customs regime in which they request the IVA and IEPS modality dd/mm/yyyy
That during the last twelve months on average they had more than two thousand five hundred employees registered with the IMSS. Average number of employees registered with the IMSS Number of employees
That the value of their machinery and equipment is greater than $100,000,000.00 in national currency. Total value of machinery and equipment $
11.2. Declare whether any credit has been determined against them by the SAT in the last twenty-four months prior to the date of submission of the application. YES NO In the affirmative case, prove that they are authorized to pay in installments in a deferred manner the omitted contributions and their accessories, or that payment in installments has been authorized, or that they have made the payment thereof.
11.3. Declare whether a resolution of improcedence of the requested IVA refunds has been issued to them in the last six months, counted from the date of submission of the corresponding certification application, whose amount does not represent more than 20% of the total authorized refunds, and/or that the denied amount does not exceed $5,000,000 (five million pesos) individually or collectively. YES NO In the affirmative case, indicate the percentage and amount that represent, of the total authorized refund requests, those in which the authority has issued a resolution of improcedence. Percentage: % Amount: $
Companies aspiring to obtain the Authorized Economic Operator modality, in addition, must comply with the following: 12.2. That, during the last two years prior to their application, they have carried out foreign trade operations. Start date of operations dd/mm/yyyy
12.3. Comply with the minimum security standards established in the form called Company Profile, as applicable: Attach the Company Profile form corresponding to each of the facilities where foreign trade operations are carried out and in magnetic media.
12.4. In case of having an authorization in the registry of certified companies, pursuant to article 100-A of the Law, in any of its sections or modalities, and request their registration in a modality different from that registry they hold, they must indicate the following: Mark with an X in the applicable box. a) Section in which their registry was granted: b) Number of official letter and date in which their registry was granted and, if applicable, the corresponding one for the last renewal: c) I declare that it is in the interest of my represented entity, in case of proving and complying with the requirements for my registration in the requested section or modality, to leave the current registry without effect. YES NO
13.2. Indicate if you carried out imports with a customs value not less than $300,000,000.00 in the semester immediately prior to that in which you submit your application. YES NO
Authorized Economic Operator Modality, Category Holding: 14.1. Companies with an IMMEX Program aspiring to obtain certification under the category of Holding, in addition to the Company Profile and what is established in rules 7.1.1. and 7.1.4., first paragraph, must comply with the following: Attach document issued by the SE, through which it is accredited that they have been designated as holding companies to integrate the manufacturing or maquila operations of two or more controlled companies, with respect to which the holding company participates directly or indirectly in their administration, control or capital, when any of the controlled companies has such direct or indirect participation on the other controlled companies and the holding company, or when a third company, whether resident in national territory or abroad, participates directly or indirectly in the administration, control or in the capital of both the holding company and the controlled companies. Attach the list of controlled companies, indicating their shareholding, their trade name or corporate name, tax domicile, RFC and the amount of imports and exports carried out by each of the companies. Attach a diagram of the shareholding and corporate structure, as well as a certified copy of the public deeds, in which the shareholding participation of the holding company and the controlled companies is stated.
Authorized Economic Operator Modality, Category Aircraft: Companies interested in obtaining the Registry in the Company Certification Scheme in the modality of Authorized Economic Operator under the category Aircraft dedicated to the elaboration, transformation, assembly, repair, maintenance and remanufacturing of aircraft, as well as their parts and components, in addition to the Company Profile and what is established in rules 7.1.1. and 7.1.4., first paragraph, must attach the following:
15.1. Indicate your IMMEX Program number and modality. IMMEX Program Number: IMMEX Program Modality:
15.2. Have the permit from the General Directorate of Civil Aeronautics of the SICT, for the establishment of aircraft workshops, when companies carry out said processes. Attach a copy of the permit from the General Directorate of Civil Aeronautics of the SICT, for the establishment of aircraft workshops, when companies carry out said processes.
16.1. Indicate your IMMEX Program number and modality. IMMEX Program Number: IMMEX Program Modality:
16.2. Indicate if during the last two years you have operated under the registry of certified companies or with certification in IVA and IEPS matters in foreign trade operations. Start date of operations under the registry of certified companies or IVA and IEPS certification. dd/mm/yyyy
16.3. Have the favorable opinion issued by the authorized Civil Association, Chambers or Confederation pursuant to rule 7.1.9., with which to prove compliance with what is provided in the Guidelines of the Electronic System for the Control of Inventories of Temporary Imports, in accordance with rule 7.1.10. Attach favorable opinion issued by the authorized Civil Association, Chambers or Confederation pursuant to rule 7.1.9. Comply with what is stated in section II of Annex 24 and with the guidelines issued to that effect by the AGACE.
16.4. Select and fill in at least one of the following options: Attach certificate of all personnel registered with the IMSS issued by the SUA, in which it can be visualized that it has at least one thousand employees registered with the IMSS. Average number of employees registered with the IMSS Number of employees
Attach documents with which to prove that it has fixed assets of machinery and equipment for an amount equivalent in national currency to 30,000,000 dollars. Total value of machinery and equipment $
Attach documentation with which to prove that the company trades on recognized markets in terms of article 16-C of the CFF. In the case that the applying company does not trade on the stock exchange, it may present the documentation that demonstrates that at least 51% of its shares with voting rights are owned directly or indirectly by a company that trades on recognized markets.
16.5. Indicate if the means of transport that you will use for the transfer of imported goods whose final destination is outside the border or border region, have tracking systems. YES NO
16.6. Indicate if you have an electronic corporate control system for your operations. YES NO
16.7. Describe the operation of the SECIIT. Attach a flowchart describing the operation of your SECIIT, which reflects that it complies with what is provided in section II of Annex 24 and with the guidelines issued to that effect by the AGACE, as well as that the customs authority has permanent and uninterrupted online electronic access, which will be verified by the customs authority during the inspection visit.
16.8. Indicate if you carry out temporary imports and return goods from the tariff fractions listed in Annex II, sections B and D of the IMMEX Decree: YES NO
17.1. Indicate if you have the Registry in the Company Certification Scheme modality IVA and IEPS in any of its categories. YES NO Category: (A, AA or AAA) Expiration date: DD/MM/YYYY Authorization official letter number:
17.2. In case of not having an IMMEX Program, you must prove compliance with the following requirements: 17.2.1. Have at least thirty employees registered with the IMSS and make the payment of the total employer-employee contributions for them. Attach certificate of all personnel registered with IMSS from the SUA and documentary support of the payment of employer-employee contributions for the last three bimesters prior to the application, of at least thirty employees.
17.2.2. List the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration in accordance with the constitution of the applying company. These must be up to date in the fulfillment of their tax obligations: RFC Full Name In their capacity as Nationality Obligated to Tax in Mexico (YES/NO)
17.2.3. Indicate if the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration in accordance with the constitution of the applying company, declared taxable income before the tax authority for the purposes of the ISR corresponding to the two fiscal years prior to the application. YES NO
18.2. Indicate if at the time of submission of your application you have the authorization of the Strategic Fiscalized Precinct regime. YES NO Indicate the expiration date and the number of the official letter with which the authorization of the Strategic Fiscalized Precinct regime was granted to you. Expiration date: DD/MM/YYYY Authorization official letter number: Attach a simple copy of the official letter through which the concession or authorization to provide the services of handling, storage and custody of foreign trade goods was granted to you.
18.3. Indicate if you are subject to a process of cancellation of the authorization of the Strategic Fiscalized Precinct regime. YES NO
19.1. Indicate if you have a valid services IMMEX Program. YES NO
19.2. Indicate if you have the Registry in the Company Certification Scheme in the modality IVA and IEPS in any of its categories. YES NO Category: (A, AA or AAA) Expiration date: DD/MM/YYYY Authorization official letter number:
19.3. Indicate if you have at least one installation for the provision of logistics services and custody of foreign trade documentation. YES NO
19.4. Indicate if you participate directly in the handling of goods and cargo management, using your own transport, distribution centers, warehouses and/or consolidation. YES NO
19.4.1. Indicate if you have third parties for the provision of customs, storage, transfer and/or distribution services of foreign trade goods, which must have the Registry in the Company Certification Scheme in the modality of Certified Commercial Partner, in any of its categories or CTPAT, granted by CBP. YES NO In the affirmative case, you must list all third parties contracted to provide on your behalf the customs, storage, transfer and/or distribution services of foreign trade goods, accompanied by the current contract that proves the commercial relationship. (Add the necessary rows according to the number of third parties you have). Name, trade name or corporate name RFC Type of Registry
20.1.1. Indicate if you request the Registry in the Company Certification Scheme in the modality of Authorized Economic Operator in any of its categories, or, if applicable, indicate if you have the registry in any of said categories: Mark with an X in the applicable box. Initial request. Has Registry.
a) In case of having a current registry, indicate the category, number of official letter and date in which your registry or the corresponding renewal was granted: Category: Date and number of official letter: b) Indicate if your registry is subject to a cancellation procedure: YES NO c) Declare under oath that the circumstances under which the registry was granted have not changed and that you continue to comply with the inherent requirements thereof: YES NO
20.1.2. Indicate if you have your own means of transport for the transfer of foreign trade goods. YES NO Attach the form called Land Auto Transporter Profile, duly filled out and in magnetic media, complying with the minimum security standards, in accordance with the filling instruction of said Profile.
20.1.3. Have the unique permit to operate private freight transport current issued by the SICT. Attach a copy of the document issued by the SICT, with which to prove that you have the unique permit to operate private freight transport current.
20.1.4. Declaration under oath, regarding the number of own units you have to operate private freight transport. Attach a free-form letter where you declare under oath the quantity of own units that the applicant has.
20.1.5. Indicate if the means of transport for the transfer of goods have tracking systems. YES NO
20.1.6. Indicate if you have the CAAT registry. YES NO Registration date: (A, AA or AAA) CAAT Registry Number: (number)
20.2. Companies that request the Registry in the Company Certification Scheme in the modality of Authorized Economic Operator that are partners of the program called CTPAT granted by the CBP and are located before the RFC can prove the requirement established in rule 7.1.4., first paragraph, fraction IV, as follows: Attach the validation report issued in a period not greater than three years from the date the application is presented, through which it proves to the applicant as a partner of the CBP (CTPAT) program, with certified-validated status, for each of the facilities validated by CBP (CTPAT), as well as attach its corresponding simple translation to Spanish.
20.2.1 Indicate if you authorized CBP (CTPAT) to share information with Mexico, through its CTPAT portal or the mechanism that the authority of that country defines: YES NO Comply with the minimum security standards established in the Company Profile format, for which the format must be delivered to the AGACE duly filled out and in magnetic media, in accordance with what is established in the profile filling instruction, only for the facilities not validated by CBP (CTPAT). The facilities that are validated by CBP (CTPAT), from which the Company Profile is not presented, must comply at all times with the minimum security standards established in the Company Profile, as provided in rule 7.2.1., third paragraph, fraction III, third paragraph and not be subject to a suspension or cancellation process by CBP (CTPAT).
Thursday, August 3, 2023 OFFICIAL GAZETTE 411
20.3. Indicate whether you have operated during the last three years as a foreign company under another company with an IMMEX Program under the sheltering modality. YES NO
20.4. Contract entered into for a minimum of three years with the company that has the IMMEX Program under the sheltering modality. Attach a copy of the contract entered into for a minimum of three years with the company that has the IMMEX Program under the sheltering modality.
21.1. Certified Commercial Partner Modality, category Terrestrial Auto Transport: Companies aspiring to obtain certification under the Certified Commercial Partner modality in the category of Terrestrial Auto Transport must comply with the requirements referred to in rule 7.1.1., with the exception of what is established in fractions VIII, X, XI, and XIV, as well as prove the requirement referred to in rule 7.1.4., first paragraph, fraction I; and with the minimum security standards referred to in article 100-A, fraction VII of the Law, as follows:
21.2. Indicate whether you carry out federal freight auto transport operations. YES NO Attach the form named Terrestrial Auto Transport Profile duly filled out and on magnetic media, complying with the minimum security standards established in the cited form.
21.3. Indicate whether, as of the date of submission of your application, you have a minimum of two years of experience in providing freight auto transport services. YES NO
21.4. Hold a valid permit issued by the SICT to provide the federal freight auto transport service. Attach a copy of the document issued by the SICT, which proves that you hold a valid permit to provide the federal freight auto transport service.
21.5. Sworn declaration regarding the number of owned or leased units used to provide the service. Attach a free-form statement declaring under oath the quantity of units the applicant has, how many are owned, and how many are leased. Attach the contract proving the leased units.
21.6. Indicate whether the means of transport that will be used for the transfer of imported goods have tracking systems. YES NO
21.7. Indicate whether, as of the date of submission of your application, you hold the CAAT registration. YES NO Registration Date: (A, AA, or AAA) CAAT Registration Number: (number)
412 OFFICIAL GAZETTE Thursday, August 3, 2023
22.1. Indicate whether you authorized CBP (C-TPAT) to share information with Mexico, through its C-TPAT portal or the mechanism that the authority of that country defines: YES NO
22.2. Indicate whether the facilities that hold CBP (C-TPAT) certification and from which the Terrestrial Auto Transport Profile must not be presented, comply with the minimum security standards: YES NO
22.3. Indicate whether, as of the date of submission of your application, you are subject to a suspension or cancellation process by CBP (C-TPAT): YES NO Attach the Terrestrial Auto Transport Profile form and on magnetic media, only for the facilities not validated by CBP (C-TPAT). The facilities that are validated by CBP (C-TPAT) from which the Terrestrial Auto Transport Profile is not presented must comply at all times with the minimum security standards established in the Terrestrial Auto Transport Profile, as provided in rule 7.2.1., fourth paragraph, fraction II, third paragraph, and must not be subject to a suspension or cancellation process by CBP (C-TPAT).
23.1. That your representatives are up to date in the fulfillment of their tax obligations, for which you will indicate the name of each of your representatives, their RFC, and whether they are up to date in the fulfillment of their tax obligations: Name RFC Indicate whether they are up to date in the fulfillment of their tax obligations
23.2. Indicate whether, as of the date of submission of your application, the customs license is active: YES NO
23.3. Indicate whether, as of the date of submission, the customs license is subject to a process of suspension, cancellation, extinction, disqualification, or voluntary suspension referred to in articles 164, 165, and 166 of the Law: YES NO
23.4. Indicate whether the customs license has been suspended, cancelled, extinguished, or disqualified in the three years prior to the submission of your application: YES NO
23.5. In the event that one or more societies have been incorporated and/or constituted, in accordance with fraction II of article 163 of the Law, repealed by Decree published in the DOF on June 25, 2018, these must be up to date in the fulfillment of tax obligations, for which you must indicate the name and RFC of said societies: YES NO Full Name (First name(s) and last name(s), without abbreviations) RFC Customs Office in which it acts
Thursday, August 3, 2023 OFFICIAL GAZETTE 413
23.6. Additional data of the customs broker. Indicate the following: Response. Customs Office of assignment. Additional authorized Customs Offices. Number of workers registered with the IMSS as of the date of this application. Number of workers registered via service provision contract. Declaration that the license I represent has a minimum of two years of experience in providing customs services. YES NO
23.7. Describe the additional services to customs management provided by the Customs Broker. (Add as many lines as necessary).
23.8. Data of the customs broker's facilities. It is necessary to indicate all facilities that belong to the license of the applying customs broker. Name and type of facilities. (Add the necessary rows according to the number of facilities). Name and/or Designation: Type of Facility: (Yards, workshops, warehouse, distribution center, administrative offices, etc.) Address: Name and/or Designation: Type of Facility: (Yards, workshops, warehouse, distribution center, administrative offices, etc.) Address:
24.1. Hold a valid concession or permit issued by the SICT to provide the freight railway transport service: Attach a copy of the document issued by the SICT, which proves that you hold a valid concession or permit to provide the freight railway transport service.
24.2. Indicate whether, as of the date of submission of your application, you have owned, leased, loaned, or other legal figure units with which you prove possession of the same (tractive equipment), that you use to provide the service: Attach a free-form statement declaring under oath the quantity of units the applicant has, how many are owned, and how many are leased. Attach the contract proving the leased units. Declaration that there is a minimum of two years of experience in providing freight transport services by rail. YES NO
414 OFFICIAL GAZETTE Thursday, August 3, 2023
24.3. Indicate whether the means of transport for the transfer of goods have tracking systems in accordance with what is established in the form named Railway Transport Profile. YES NO
25.1. Indicate the name and/or designation of each Industrial Park for which registration is requested and that belongs to and operates under the same RFC as the corporate entity. The housed facilities can be industrial plants, warehouses, distribution centers, etc., and must carry out foreign trade operations. (Add as many rows as necessary). Name and/or Designation of the Industrial Park RFC Type of facility Address of the facility
25.2. Hold the Environmental Impact Manifestation: Attach the document issued by SEMARNAT on the environmental impact in accordance with the Standard NMX-R-046-SCFI-2015, Industrial Parks-Specifications.
26.1. Indicate whether, at the time of submission of your application, you hold the Supervised Warehouse authorization. YES NO Indicate the expiration date and the number of the official document with which the Supervised Warehouse authorization was granted to you: Expiration Date: DD/MM/YYYY Authorization Official Document Number: Attach a simple copy of the official document through which the authorization for the elaboration, transformation, or repair in a supervised warehouse was granted to you.
26.2. Indicate whether, at the time of submission of your application, you are subject to a process of cancellation of the Supervised Warehouse authorization. YES NO
Thursday, August 3, 2023 OFFICIAL GAZETTE 415
27.1. Mark with an X to whom the aircraft in which you transport documents and goods belong: Owned Subsidiary Branch Parent Company Indicate the name of the owner of the aircraft in which you transport documents and goods. (Add as many boxes as necessary). Name Subsidiary, Branch, or Parent Company Attach a service contract, with a minimum validity of five years and not less than one year from the date of your application, entered into directly or through your parent companies, branches, or subsidiaries, with a concessionaire or permit holder duly authorized by the SICT, through which you make available for dedicated use of the activities of the courier or parcel company at least 30 aircraft and that provide regular frequencies to the airports where said company carries out the dispatch of documents or goods. Attach the document issued by the General Directorate of Civil Aeronautics of the SICT in favor of the concessionaire or permit holder, which proves that they have authorized or registered the air routes or airways within national airspace.
27.2. Mark with an X who operates the transport of aircraft: Applicant Subsidiary Branch Parent Company Attach the document issued by the General Directorate of Civil Aeronautics of the SICT, which proves that you hold the registration of air routes or airways within national airspace.
27.3. Indicate whether, at the time of submission of your application, you hold the concession or authorization to provide the services of handling, storage, and custody of foreign trade goods in accordance with articles 14 and 14-A of the Law. YES NO Indicate the expiration date and the number of the official document with which the concession or authorization to provide the services of handling, storage, and custody of foreign trade goods in accordance with articles 14 and 14-A of the Law was granted to you. Expiration Date: DD/MM/YYYY Authorization Official Document Number:
27.4. Indicate whether, as of the date of submission of your application, you have a minimum investment in fixed assets equivalent in national currency to 1,000,000 dollars. YES NO Attach the document which proves that as of the date of submission of your application, you have a minimum investment in fixed assets equivalent in national currency to 1,000,000 dollars.
27.5. Indicate whether, for the purposes of this category, accreditation is made as a group. YES NO Indicate the name of the companies that are part of the group. (Add as many boxes as necessary). Name RFC
416 OFFICIAL GAZETTE Thursday, August 3, 2023
27.6. Indicate the name of the companies that are part of the group that holds the aircraft. (Add as many boxes as necessary). Name RFC Attach the document which proves that they hold aircraft for the transport of documents and goods, via a service contract, entered into directly or through an operating company that is part of the same group, that holds a concession or permit granted by the SICT, through which it makes available to you for exclusive use of the courier and parcel activities at least three aircraft and provides regular frequencies to the airports where the courier and parcel companies carry out the dispatch of the documents or goods. Attach the permit from the SICT issued in favor of the company that is part of the group.
27.7. Indicate the name of the companies that are part of the group, which operate the transport of the aircraft indicated in the previous fraction, have their air routes or airways authorized or registered within national airspace before the General Directorate of Civil Aeronautics of the SICT. Name RFC Attach the document issued by the General Directorate of Civil Aeronautics of the SICT, which proves that they have authorized or registered the air routes or airways within national airspace.
27.8. Indicate the name of the companies that are part of the group that hold the concession or authorization to provide the services of handling, storage, and custody of foreign trade goods in accordance with articles 14 and 14-A of the Law. Name RFC Indicate the expiration date and the number of the official document with which the concession or authorization to provide the services of handling, storage, and custody of foreign trade goods in accordance with articles 14 and 14-A of the Law was granted to you. Expiration Date: DD/MM/YYYY Authorization Official Document Number:
28.1. Indicate whether, at the time of submission of your application, you hold the authorization to provide the service of storage of goods in the fiscal deposit regime. YES NO Indicate the expiration date and the number of the official document with which the authorization to provide the service of storage of goods in the fiscal deposit regime was granted to you: Expiration Date: DD/MM/YYYY Authorization Official Document Number: Attach a simple copy of the official document through which the authorization to provide the service of storage of goods in the fiscal deposit regime was granted to you.
28.2. Indicate whether, at the time of submission of your application, you are subject to a process of cancellation of the authorization to provide the service of storage of goods in the fiscal deposit regime. YES NO
Thursday, August 3, 2023 OFFICIAL GAZETTE 417
Mutual recognition for the Authorized Economic Operator and Certified Commercial Partner modalities. The adoption by Mexico of the norms established in the SAFE Framework of Standards for Securing and Facilitating Global Trade published by the WCO, which incorporates practices and norms in the matter of security, has as one of its objectives, to achieve Mutual Recognition with those countries that have a similar program in the matter of security, that meet the condition of Authorized Economic Operators according to the SAFE Framework and the legislation of each country. Therefore, as part of the strategy to avoid duplication of security controls and to contribute significantly to the facilitation and control of goods circulating in the international supply chain, it is necessary to have the participation of those who manage to obtain the Registration in the Company Certification Scheme and authorize the exchange of information that allows enriching the computer systems, eliminating and/or reducing the redundancy and/or duplication of efforts in the registration process. For the above and in accordance with what is provided in article 21 of the Federal Law of Transparency and Access to Public Governmental Information, I authorize the obligated subject named SAT, through the AGACE, to share, disseminate or distribute with other national or foreign authorities the personal data and other information of the company that I represent, and that is generated during the course in which the same is registered in the Company Certification Scheme. If I authorize I do not authorize
List of Certified Commercial Partners. With the aim of creating safer supply chains, a list will be established with the companies that have obtained certification as Commercial Partners, which will be published on the SAT Portal and will include the general data that the company authorizes, as well as the status of its certification, which may be consulted by companies that have obtained their registration in the Company Certification Register. Indicate the general data you authorize to publish: YES NO RFC. Name or Corporate Name. Tax address. If authorized, specify the contact data you wish to publish: Website. Contact email. Contact phone number(s).
Classification of Information. The information provided during this procedure for the Registration in the Company Certification Scheme is classified by the company as (Mark with an X in the box the selected option): Public Confidential Once the above has been stated, the SAT is requested, through the AGACE, to carry out the inspections referred to in rule 7.1.1., fraction IX, at the facilities where production processes are carried out with the purpose of verifying the information reflected in this application and in the Profile corresponding to rules 7.1.4., first paragraph, fraction IV and third, fraction IV and 7.1.5., fractions I, subsection b), II, subsection b), III, subsection a), IV, subsection a), V, subsection b), VI subsection e) and VII, subsection b) which I attach to this application. Under oath, I declare that the data recorded in this document are true and that the attached documents are true and that the powers granted to me to represent the applicant have not been modified and/or revoked. NAME AND SIGNATURE OF THE LEGAL REPRESENTATIVE OF THE APPLICANT LEGAL ENTITY
418 OFFICIAL GAZETTE Thursday, August 3, 2023
INSTRUCTIONS Clarifying notes:
MODALITY IN WHICH YOU REQUEST YOUR REGISTRATION You must select the modality and item in which you wish to obtain the Registration. For those companies that have obtained an IMMEX program for the first time for a pre-operational period; an authorization for the establishment of a tax deposit to undergo the process of assembly and manufacturing of vehicles; an authorization for the regime of elaboration, transformation or repair in a supervised tax facility or authorization for the strategic supervised tax facility regime; within the twelve months prior to the date of their registration application, only once, they may apply for the Registration only for the temporary importation of fixed assets, complying with the requirements indicated in rule 7.1.1. and those established in rule 7.1.2., with the exception of fraction II of section A; fraction II of section C and fraction II of section D; in which case, the Registration will be granted for a period of up to six months, which may be extended, only once, for an additional period of three months, for which they must present their application to the AGACE, up to five days before the expiration of the Registration, in writing in terms of rule 1.2.2., first paragraph, granting such extension the day after the expiration of the registration. Once you have the necessary infrastructure to carry out the operation of the IMMEX program, the industrial process in accordance with the modality of your program and/or the operation as a tax deposit to undergo the process of assembly and manufacturing of vehicles; of elaboration, transformation or repair in a supervised tax facility or of strategic supervised tax facility, you must inform the AGACE in writing in terms of rule 1.2.2., first paragraph.
CUSTOMS REGIME UNDER WHICH YOU WILL REQUEST REGISTRATION IN THE IVA AND IEPS MODALITY Select the customs regime.
GROUP COMPANIES Companies that are part of a group, for the purposes of rule 7.1.7. In the case of those companies that belong to the same group, they may prove personnel, infrastructure and investment amounts through any of the companies in the same group. To do so, they must indicate the name and RFC of the companies that are part of the group, attach a diagram of the shareholding and corporate structure, as well as copies of the public deeds, in which the shareholding participation of the companies that are part of the group is recorded. During inspection visits to the applicant company, the verifier may request the certified copy of the public deed in which the shareholding participation is recorded. Only in the case of the companies mentioned in rules 7.1.2., section B and 7.1.4., first paragraph, fraction II, the requirement of seniority may be proven with any of the companies that are part of the group that has had operations under the IMMEX Program, in the last twelve months and/or two years, respectively, provided that the latter attaches a writing in which it assumes joint and several liability referred to in fraction VIII, of article 26 of the CFF, of the tax credits that may arise. Said writing must be transmitted as an attachment through Digital Counter, and a copy of the power of attorney with which it proves the personality of the legal representative of the company that assumes the joint and several liability must be exhibited. You must mark the type of concept that proves you as a company member of a group, being able to choose one or more of the options indicated.
Thursday, August 3, 2023 OFFICIAL GAZETTE 419 Indicate, if applicable, the type of information that the applicant proves, through any of the companies that are part of the same group.
SHELTER COMPANIES Companies that have operated during the last three fiscal years, for the purposes of rule 7.1.8. For the purposes of companies constituted in accordance with Mexican legislation and that have operated in the last three fiscal years in terms of article 183 of the Income Tax Law, they may obtain the Registration in the Company Certification Scheme, IVA and IEPS modality, any item, and may prove the requirements of personnel, infrastructure and investment amounts (investment in national territory), through the company that has the maquila program under the shelter modality with which it has operated for the last three years, provided that, the company with the maquila program, under the shelter modality, with which it has operated, has the Registration in the Company Certification Scheme, IVA and IEPS modality, item AAA and is not suspended or subject to the start of a cancellation procedure, the applicant has an IMMEX Program, obtained for the first time during the last twelve months prior to its application and attaches the following documents: a) Copy of the contract celebrated, for a minimum validity of three years, with the company that has the IMMEX Program under the Shelter modality. b) Declaration, under oath, signed by the legal representative of the company that has the IMMEX Program under the Shelter modality, regarding the temporality in which the applicant operated as a foreign company under its IMMEX Program in shelter modality. c) Copy of the power of attorney with which it proves the personality of the legal representative of the company with the IMMEX Program under the Shelter modality. You must manifest the denomination or corporate name, RFC and IMMEX Program number of the company that has the IMMEX Program in the shelter modality. Indicate the type of concept you wish to prove with the company with the IMMEX Program in the shelter modality. You may mark more than one option.
DATA OF THE APPLICANT NATURAL OR LEGAL PERSON.
420 OFFICIAL GAZETTE Thursday, August 3, 2023 In the event that operational liaison changes are made, these must be notified to the AGACE through the email: certification.iva.ieps@sat.gob.mx, within a term of five days for the IVA and IEPS modality. In the event that operational liaison changes are made, these must be notified to the AGACE through the email: oeamexico@sat.gob.mx, within a term of five days for the Commercial and Importer, Authorized Economic Operator and Certified Commercial Partner modalities. 3.2. Person authorized as operational liaison (Substitute). In addition to the previous field, you must establish a substitute for the operational liaison, meeting the same requirements as the previous one. 4. General requirements that must be met in any modality in which you request your Registration in the Company Certification Scheme. 4.1. Indicate if you are up to date in the fulfillment of your tax and customs obligations. You must answer what corresponds. 4.2. Indicate if you authorized the SAT to make public its positive opinion on the fulfillment of obligations. You must answer what corresponds. 4.3. Certificate of the totality of personnel registered with the IMSS, of the SUA and the payment receipt of the employer-employee quotas, of the last bimonthly period prior to the date of submission of the application, as well as complying with the obligation to withhold and pay the ISR of the workers. a) To prove the totality of personnel, you must attach from all employer records certificates of the totality of personnel registered with the IMSS, of the SUA. The company may attach the first page (where the corporate name and period appear) and the last page (where the totality of employees registered with the IMSS is recorded).
Thursday, August 3, 2023 OFFICIAL GAZETTE 421
For the case of companies that request registration in the Commercializer and Importer modality, they may present a file containing only the name and address of their main foreign clients and suppliers with whom they carried out foreign trade operations related to the regime under which they request registration, during the last twelve months.
In the case of not having clients and/or suppliers abroad, linked to the process under the regime under which registration is requested, they must present a free-form statement, manifesting this.
Companies that have obtained their IMMEX Program for the first time before the SE during the last twelve months prior to the submission of the application will not be subject to compliance with this requirement, provided that they have not had foreign trade operations.
4.10. Attach a file containing the name and RFC of your suppliers of inputs acquired in national territory, linked to the process under the regime under which registration is requested, for the last six months, counted from the date of submission of the application.
You must attach a file containing the name and RFC of your suppliers of inputs acquired in national territory, linked to the process under the regime under which registration is requested, for the last six months, counted from the date of submission of the application.
For this purpose, national suppliers are also considered to be those companies with an IMMEX Program that transfer goods to them through virtual operations, in terms of Annex 22, regardless of whether the suppliers or sellers are residents abroad who deliver in national territory through a company with an IMMEX Program, for which you must make the distinction of the companies with which you carry out virtual transfers.
For the case of companies that request registration in the Commercializer and Importer modality, they may present a file containing only the name and RFC of their main suppliers of inputs acquired in national territory, linked to the process under the regime under which registration is requested, for the last six months, counted from the date of submission of the application.
In the case of not having suppliers of inputs acquired in national territory, linked to the process under the regime under which registration is requested, they must present a free-form statement, manifesting this.
Companies that have obtained their IMMEX Program for the first time before the SE during the last twelve months prior to the submission of the application will not be subject to compliance with this requirement, provided that they have not had foreign trade operations.
4.11. Accredit that you have the legal use or enjoyment of the property or properties where the productive processes or the provision of the service, as applicable, take place, in which a mandatory term of at least one year of validity is established, and that you have a remaining validity of at least eight months.
You must declare the address or addresses where the productive processes or the provision of the service, as applicable, take place, from which you intend to accredit the legal use or enjoyment, and attach a contract or title of ownership. Such address must be registered with the SAT.
Attach documentation according to applicable legislation that supports the ownership, use, or temporary enjoyment of the property or properties where the productive processes or the provision of services, as applicable, take place, in which a mandatory term of at least one year of validity is established, and that you have a remaining validity of at least eight months from the date of submission of the application.
It is important that the address subject to the contract or title of ownership with which you intend to accredit the legal use or enjoyment fully coincides with any of the addresses registered with the SAT. When the addresses do not fully coincide, you must accompany the title of ownership with documentation that accredits that it is the same declared with the SAT, for example: property tax bill as long as it is related to the cadastral key observed in the title of ownership; document issued by the cadastral office in which the address and the name of the owner are stated, relating to the title of ownership by the cadastral key and/or the description of the property; document from the Public Property Registry where the address and the name of the owner are stated; certificate of facts issued by a Public Notary in which said Notary has had the title of ownership in view, has been present at the property and verifies that the address visited is the same as the one presented in the title.
For the case of contracts where the address does not fully coincide with any of the addresses registered with the SAT, you may accompany them with an addendum or modifying agreement in which the address fully coincides.
In the case of having a sublease contract, you must exhibit the main lease contract containing a validity equal to or greater than that of the sublease contract, and you must also exhibit the documentation with which you accredit the general authorization to sublease the property.
During inspection and supervision visits to the applicant company, the verifier may request the CFDIs issued for the payment of the lease of the property or properties where the productive processes and/or the provision of the service and/or economic and foreign trade activities take place.
422 OFFICIAL GAZETTE Thursday, August 3, 2023
4.12. Indicate if the SAT has filed a criminal complaint or denunciation against the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration of the applicant company or declaration of prejudice, as applicable, during the last three years prior to the submission of the application.
You must answer what corresponds.
4.13. Indicate if you have an inventory control system, for the registration of your foreign trade operations.
Regardless of the type of inventory control system in question, you must capture the name or data for its identification and indicate its place of residence, that is, any establishment, branch, plant, etc., where you have access to all the functions and information of the inventory control system.
In the event that you have more than one inventory control system, you may indicate the data of all of them by adding rows in the table.
The inventory control system must comply with the provisions provided for in Annex 24 and you must attach a report of balances of temporary import merchandise or merchandise subject to foreign trade operations, for a period of one month, which is within the three months prior to the date of the present application. The minimum information required for the identification of the operations, by way of example and not limitation, is as follows:
IMPORTATION ENTRY BALANCES No. of entry Date of payment or date of entry Entry Key Tariff Fraction Quantity imported Value of importation Balance Value of Balance (15 digits) dd/mm/yy As declared in the reference entry Units MXN Units MXN 29/11/31 IN 8708.95.02 5200 $125,000.00 50500 $124,376.00
Companies that have obtained their IMMEX Program for the first time before the SE, within the twelve months prior to the date of submission of their application, will not be obliged to present the balance report mentioned in the previous paragraph, however, they must accredit that they have inventory control in accordance with article 59, fraction I of the Law, in relation to Annex 24.
4.14. Indicate if you keep accounting in electronic media in accordance with article 28, fraction III, of the CFF and rule 2.8.1.5. of the RMF.
You must answer what corresponds.
4.15. Indicate if you enter your accounting information monthly through the SAT portal, in accordance with article 28, fraction IV, of the CFF and rule 2.8.1.6. of the RMF.
You must answer what corresponds.
4.16. Indicate if the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration in accordance with the constitution of the applicant company, are obliged to pay taxes in Mexico and not obliged to pay taxes in Mexico.
You must list all partners and/or shareholders:
For those not obliged to pay taxes in Mexico, you must take the following into account:
Thursday, August 3, 2023 OFFICIAL GAZETTE 423
The documentation exhibited to accredit that the members of the company are not obliged to pay taxes in Mexico must contain the full and correct name of the declared person; in the event that the document exhibited does not contain the name exactly as declared in the initial application, which must coincide with the constitutive act or respective modification; such documentation cannot be considered to accredit this requirement.
4.17. Indicate if your partners or shareholders and members of the administration are not linked to any company whose Registration in the Company Certification Scheme has been cancelled, in accordance with fractions V, VI and VII of section A; II and III of section B of rule 7.2.4.; and/or VI, VII and XI of rule 7.2.5.
You must answer what corresponds.
4.18. Indicate if you have made the payment of the right referred to in article 40, subsection m), of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application:
You must answer what corresponds. And you must record the amount paid, the payment date, bank operation number and the corresponding payment key.
5.1. Provide certificates of personnel registered with the IMSS, of the SUA, and the documentary support for the payment of the entire employer-employee contributions of at least ten employees through capture line of the last bimonthly period prior to your application of the applicant.
a) You must attach certificates of at least ten contributors registered with the IMSS, of the SUA. The company may attach the first page (where the social denomination and the period appear) and the last page (where the total number of employees registered with the IMSS is stated) of the last bimonthly period prior to your application.
b) You must attach the documentary support for the payment of employer-employee contributions downloaded by the SIPARE or payment receipt that is consistent with the SUA information. Those receipts that contain legends stating that they have no fiscal or legal effects will not be valid to accredit the requirement.
c) You must present a list with the name and RFC of at least ten employees of the applicant that can be visualized in the certificates of personnel registered with the IMSS, of the SUA presented, to whom you have issued the payroll CFDIs.
The authority will verify the issuance of the CFDIs, in the event that any inconsistency is detected, the authority may request that you exhibit documentation that accredits its corresponding issuance, at all times.
Companies that have obtained their IMMEX Program for the first time before the SE, within the twelve months prior to the submission of the application, may comply with the requirement with the document that supports the hiring of employees; accrediting the issuance of the payroll CFDIs issued by the applicant to the hired workers, it will not be necessary to attach documentation to the application, the authority will verify the issuance of the CFDIs, in the event that it is detected that they have not issued them, the authority may request that you exhibit documentation that accredits its corresponding issuance, at all times.
5.2. Accredit the investment in national territory.
You must capture the global value of each of the concepts that apply to you (real estate, movable property).
This value can be the current value of the goods or the customs value if they come from temporary imports, or a combination of both. It will not be necessary to attach documentation to the application, since during the initial inspection visit or the supervision visits on compliance, the authority may request that you exhibit documentation that accredits the investment in national territory such as lease contracts accompanied by their CFDIs, titles of ownership, import entries, among others.
5.3. State if you previously had Certification in matters of IVA and IEPS, Registration in the Company Certification Scheme under the IVA and IEPS modality or Guarantee of the fiscal interest of IVA and IEPS.
5.4. In the affirmative case, you must indicate if you are up to date in the fulfillment of the obligations related to Annex 30, on the registration with which you had.
5.5. State if you have suppliers that are on the list of companies published by the SAT in terms of article 69-B, fourth paragraph of the CFF.
Suppliers are considered to be those taxpayers who provide services or produce, commercialize or deliver goods. Companies with an IMMEX Program that transfer goods to them through virtual entries are also considered suppliers, regardless of whether the suppliers or sellers are residents abroad who deliver in national territory through a company with an IMMEX Program, for which you must make the distinction of the companies with which you carry out virtual transfers.
424 OFFICIAL GAZETTE Thursday, August 3, 2023
6.1. Indicate the number of your IMMEX Program and the modality.
You must capture your IMMEX Program number and the modality under which you are authorized (industrial, services, shelter, outsourcing, or holding).
You must state if you have carried out operations under your IMMEX program.
6.2. Indicate if you have the necessary infrastructure to carry out operations of the IMMEX Program, to the industrial or service process in accordance with the Program modality.
You must answer what corresponds.
You must accredit through CFDIs, titles of ownership, import entries, own and/or contracts that support that you have the legal use and/or enjoyment of the machinery and equipment with their respective CFDIs that support the payment, as applicable, to carry out the productive process and/or service. Likewise, you must attach photographic evidence of your productive plant, as well as of your productive process. In the case of those companies that intend to accredit through the group figure, such documentation must be in the name of the company with which it is part of the group.
In the case of companies that have an IMMEX Program, in the outsourcing modality, they can accredit the requirement through one of the companies that performs the manufacturing for them, for which they must present the current contract with which they accredit the provision of the service; the CFDIs, issued by the provider for the concept of payment of the service and the authorization issued by the SE, for the performance of manufacturing.
6.3. Indicate if during the last twelve months you have temporarily imported merchandise and that, at least 60% of the temporary imports of inputs carried out during the same period, were transformed and returned, returned in their same state, transferred, destroyed, or a service was provided to them.
You must capture the total customs value in national currency of your temporary imports of inputs carried out during the last twelve months.
The last twelve months can be computed from the month immediately preceding the month in which the company presents its application.
Likewise, you must declare the value in national currency (commercial value) of the discharges made for each concept (returns, virtual transfers, waste, as well as Certificates of Transfer of Merchandise (CTM)), the customs value of the temporarily imported inputs included in each concept and the percentage that represents with respect to the total of temporary imports that have been captured in the corresponding field.
In the event that you have declared that you carry out Certificates of Transfer of Merchandise (CTM), you must attach a file with the names and addresses of the companies to which you transferred merchandise through Certificates of Transfer of Merchandise (CTM), as well as the amounts in national currency and, if applicable, two Certificates of Transfer of Merchandise (CTM).
Companies that have obtained their IMMEX Program granted by the SE for the first time during the twelve months prior to the submission of the application will not be subject to compliance with this requirement.
6.4. Description of activities related to productive processes or provision of services in accordance with the Program modality.
You must attach a detailed description of your main productive process (in terms of value or volume of production) that shows step by step the flow of temporarily imported merchandise, from the point of origin, the point of entry into the country (customs), its receipt in the company, materials used with tariff fraction, storage, its integration into the productive process, performance of its productive process or service exit point (customs) and its destination (country) or discharge (return, virtual transfer, certificate of destruction of waste, Certificates of Transfer of Merchandise (CTM), among others), as well as the complementary processes and services that add value to your final product (submanufacturing processes).
The description can be presented in the form of a flowchart, as long as it contains the description of each step in accordance with the previous paragraph.
6.5. Continuity of the export project.
You must attach a maquila contract, purchase and sale contract, purchase order or service contract, or firm orders, that accredit the continuity of the export project; in said documents, the social denomination of the applicant, the validity of the document, the signatures of the parties must be identified and if it is in a language other than Spanish, it must be accompanied by a simple or certified translation, as applicable, to Spanish. Documents with a date prior to one month will not be taken into account.
Companies with which you carry out the operations mentioned in the previous paragraph must be on your list of foreign clients, in the event of carrying out export operations with entry key V1, of Appendix 2 of Annex 22, additionally you must present a free-form statement signed by the legal representative of the applicant company where it is stated that you carry out said operations, with which company you carry them out and at least one entry number.
Thursday, August 3, 2023 OFFICIAL GAZETTE 425
In the case of carrying out Certificates of Transfer of Goods (CTM), two copies of said certificates must be attached.
They cannot submit the application under the IVA and IEPS modality if they have operated for less than twelve months prior to the submission of said application, except for those that certify being part of a group.
For companies that are part of a group, they must present a document in which one of the companies that make up the group and has been operating for more than twelve months under the IMMEX Program, assumes the joint liability referred to in fraction VIII of article 26 of the Federal Tax Code (CFF), for the tax credits that may arise; as well as they must exhibit a copy of the power of attorney with which they certify the legal personality of the legal representative of the company that assumes the joint liability.
8.1. Indicate if you have authorization to operate the fiscal deposit regime for the vehicle assembly and manufacturing process for companies in the terminal automotive industry currently in force. You must answer what corresponds.
8.2. Indicate if you are subject to a cancellation process. You must answer what corresponds.
8.3. Indicate if you have the necessary infrastructure to carry out operations, in accordance with your customs regime. You must answer what corresponds. You must certify through CFDI (Electronic Fiscal Receipts), property titles, import declarations, own and/or contracts that cover that you have the legal use and/or enjoyment of the machinery and equipment with their respective CFDI that cover the payment, as appropriate, to carry out the productive process and/or service, in case the authority so requires. In the case of those companies that intend to certify through the group figure, said documentation must be in the name of the company with which it is part of the group.
8.4. Description of activities related to productive processes and/or provision of services in accordance with your customs regime. You must attach a detailed description of your main productive process and/or provision of the service (in terms of value or production volume) that shows step by step the flow of temporarily imported goods, from the point of origin, the point of entry into the country (customs), its receipt at the company, materials used with tariff fraction, storage, its integration into the productive process, carrying out of its productive process or service, point of exit (customs) and its destination (country) or discharge (return, virtual transfer, certificates of destruction of waste, Certificates of Transfer of Goods (CTM), among others), as well as complementary processes and services that add value to your final product (submanufacturing processes). The description may be presented in the form of a flowchart, provided that it contains the description of each step in accordance with the previous paragraph.
8.5. Continuity of the export project. You must attach a maquila contract, sales contract, purchase order or service order, or firm orders in force, that certify the continuity of the export project; in said documents, the legal name of the applicant must be identified, the validity of the document, the signatures of the parties and if it is in a language other than Spanish, it must be accompanied by a simple or certified translation, as appropriate, to Spanish. Documents with a date earlier than one month will not be taken into account. The companies with which the operations mentioned in the previous paragraph are carried out must be found in their list of foreign clients, in the case of carrying out export operations with V1 declaration key, from appendix 2 of Annex 22, additionally you must present a free-form document in terms of rule 1.2.2., first paragraph, signed by the legal representative of the applicant company where it is stated that it carries out said operations, with which company it carries them out and at least one declaration number. In the case of carrying out Certificates of Transfer of Goods (CTM), two copies of said certificates must be attached.
9.1. Indicate if you have the current authorization, transformation or repair in a supervised precinct or strategic supervised precinct. You must attach a copy of your current authorization.
9.2. Indicate if you are subject to a cancellation process. You must answer what corresponds.
9.3. Indicate if you have the necessary infrastructure to carry out operations, in accordance with your customs regime. You must answer what corresponds. You must certify through CFDI (Electronic Fiscal Receipts), property titles, import declarations, own and/or contracts that cover that you have the legal use and/or enjoyment of the machinery and equipment with their respective CFDI that cover the payment, as appropriate, to carry out the productive process and/or service, in case the authority so requires. In the case of those companies that intend to certify through the group figure, said documentation must be in the name of the company with which it is part of the group.
9.4. Description of activities related to productive processes and/or provision of services in accordance with your customs regime. You must attach a detailed description of your main productive process and/or provision of the service (in terms of value or production volume) that shows step by step the flow of temporarily imported goods, from the point of origin, the point of entry into the country (customs), its receipt at the company, materials used with tariff fraction and NICO, storage, its integration into the productive process, carrying out of its productive process or service, point of exit (customs) and its destination (country) or discharge (return, virtual transfer, certificates of destruction of waste, Certificates of Transfer of Goods (CTM), among others), as well as complementary processes and services that add value to your final product (submanufacturing processes). The description may be presented in the form of a flowchart, provided that it contains the description of each step in accordance with the previous paragraph.
9.5. Continuity of the export project. You must attach a maquila contract, sales contract, purchase order or service order, or firm orders in force, that certify the continuity of the export project; in said documents, the legal name of the applicant must be identified, the validity of the document, the signatures of the parties and if it is in a language other than Spanish, it must be accompanied by a simple or certified translation, as appropriate, to Spanish. Documents with a date earlier than one month will not be taken into account. The companies with which the operations mentioned in the previous paragraph are carried out must be found in their list of foreign clients, in the case of carrying out export operations with V1 declaration key, from appendix 2 of Annex 22, additionally you must present a free-form document in terms of rule 1.2.2., signed by the legal representative of the applicant company where it is stated that it carries out said operations, with which company it carries them out and at least one declaration number. In the case of carrying out Certificates of Transfer of Goods (CTM), two copies of said certificates must be attached.
10.1. Select and fill in at least one of the following options. The applicant company must comply with at least one of the three scenarios, however, it may choose more than one option. In each of the scenarios, the applicant company must certify its compliance:
10.2. State if any credit has been notified to you by the SAT (Tax Administration Service) in the twelve months prior to the date of submission of the application. If affirmative, you must attach a simple copy of the authorization for payment in installments, partial payments or deferred, or the respective payment receipt.
10.3. State if a resolution of impropriety of the requested IVA refunds has been issued to you in the last six months, counted from the date of submission of the corresponding certification request, whose amount does not represent more than 20% of the total authorized refunds, and/or that the denied amount does not exceed $5,000,000.00 in National Currency individually or collectively. If affirmative, indicate the percentage that the improper amount represents in relation to the amount of authorized refunds, in the last six months. The improper amount must not exceed 20% of the authorized amount and said percentage must not be greater than $5,000,000.00 in national currency individually or collectively.
Thursday, August 3, 2023 OFFICIAL GAZETTE 427
11.1. Select and fill in at least one of the following options. The applicant company must comply with at least one of the three scenarios, however, it may choose more than one option. In each of the scenarios, the applicant company must certify its compliance:
11.2. State if any credit has been notified to you by the SAT (Tax Administration Service) in the twenty-four months prior to the date of submission of the application. If affirmative, you must attach a simple copy of the authorization for payment in installments, partial payments or deferred, or the respective payment receipt.
11.3. State if a resolution of impropriety of the requested IVA refunds has been issued to you in the last six months, counted from the date of submission of the corresponding certification request, whose amount does not represent more than 20% of the total authorized refunds, and/or that the denied amount does not exceed five million in national currency individually or collectively. If affirmative, indicate the percentage that the improper amount represents in relation to the amount of authorized refunds, in the last six months. The improper amount must not exceed 20% of the authorized amount and said percentage must not be greater than 5 million in national currency individually or collectively.
12.1. State the name and RFC (Taxpayers' Registry Code) of the authorized transport companies to carry out the transfer of foreign trade goods: You must indicate the name, RFC and CAAT registration of each of the authorized transport companies to carry out the transfer of foreign trade goods.
12.2. You must record the start date of operations in order to certify that you have carried out foreign trade operations during the last two years.
12.3. Comply with the minimum security standards established in the form called Company Profile: You must present duly filled out the form called Company Profile and on magnetic media, for each of the facilities.
12.4. You must state if prior to the submission of your application, you have an authorization in the registry of certified companies, in accordance with article 100-A of the Law, in any of its Sections or modalities. You must indicate the Section in which your registration was granted, the number of the official letter and the date on which it was granted and, if applicable, the corresponding one for the last renewal, as well as state if it is the interest of the applicant that, in case of certifying and complying with the requirements for the requested inscription, leave the current registration without effect.
13.1. Indicate if you have the IMMEX Program. You must answer what corresponds.
13.2. Indicate if you carried out imports for a customs value not less than $300,000,000.00, in the semester immediately preceding that in which you submit your application. You must answer what corresponds.
14.1. Companies with the IMMEX Program that aspire to obtain certification under the Holding Company category, in addition to the Company Profile and what is established in rules 7.1.1. and 7.1.4., first paragraph, must comply with the following: Attach a document issued by the SE (Secretariat of Economy), through which it certifies that they have been designated as holding companies to integrate the manufacturing or maquila operations of two or more controlled societies, with respect to which the holding company participates directly or indirectly in their administration, control or capital, when any of the controlled companies has such direct or indirect participation on the other controlled companies and the holding company, or when a third company, whether resident in national territory or abroad, participates directly or indirectly in the administration, control or in the capital of both the holding company and the controlled societies.
428 OFFICIAL GAZETTE Thursday, August 3, 2023
Attach a file with the list of controlled societies, indicating their shareholding participation, their name or legal name, tax domicile, RFC and the amount of imports and exports carried out by each of the societies. A file containing a diagram of the shareholding and corporate structure, as well as a copy of the public deeds, in which the shareholding participation of the holding company and the controlled societies is recorded. During inspection visits to the applicant company, the verifier may request the certified copy of the public deed in which the shareholding participation is recorded.
15.1. Indicate your IMMEX Program number and modality. You must indicate your IMMEX Program number and modality.
15.2. Have the permit from the General Directorate of Civil Aeronautics of the SICT (Secretariat of Infrastructure, Communications and Transportation) for the establishment of aircraft workshops. Attach a copy of the permit issued by the General Directorate of Civil Aeronautics of the SICT, for the establishment of aircraft workshops, when companies carry out said processes.
16.1. Indicate your IMMEX Program number and modality. You must indicate your IMMEX Program number and modality.
16.2. Indicate if during the last two years you have operated under the Registry of Certified Companies or with certification in IVA and IEPS matters for foreign trade operations. You must answer what corresponds.
16.3. Have the favorable report issued by the authorized Civil Association, Chambers or Confederation in accordance with rule 7.1.9., with which you certify compliance with what is provided in the Guidelines of the Electronic System for the Control of Inventories of Temporary Imports, in accordance with rule 7.1.10. Attach favorable report issued by the authorized Civil Association, Chambers or Confederation in accordance with rule 7.1.9. Comply with what is stated in Section II, of Annex 24 and with the guidelines issued by the AGACE to that effect. Indicate if you have an inventory control system, for the registration of your foreign trade operations, in accordance with what is stated in Section II, of Annex 24 and with the guidelines issued by the AGACE to that effect. In case of having an inventory control system in accordance with the provisions provided by Annex 24, you must attach a report of balances of temporarily imported goods or goods subject to foreign trade operations, for a period of one month, which is within the three months prior to the date of the present application. The minimum information required for the identification of operations, by way of example and not limitation, is the following:
IMPORT DECLARATION BALANCES
| No. of declaration (15 digits) | Payment Date | Declaration Key | Tariff Fraction | Imported Quantity | Import Value | Balance | Balance Value |
|---|---|---|---|---|---|---|---|
| dd/mm/aa | As declared in the reference import declaration | Units | MXN | Units | MXN | ||
| 29/11/31 | IN | 8708.95.02 | 5200 | $125,000.00 | 50500 | $124,376.00 |
16.4. You must certify at least one of the following scenarios, however, you may choose more than one option: a) Attach a certificate of all personnel registered with the IMSS, from the SUA. In order to avoid attaching the entire SUA, the company may attach the first page (where the social denomination and period appear) and the last page (where the total number of employees registered with the IMSS is recorded). b) Attach a document that certifies that you have fixed assets of machinery and equipment for an amount equivalent in national currency to 30,000,000 dollars. c) Attach documentation that certifies that the company trades in recognized markets in terms of article 16-C of the CFF. In the case that the applicant company does not trade on the stock exchange, it may present the documentation that demonstrates that at least 51% of its shares with voting rights are owned directly or indirectly by a company that trades in recognized markets.
16.5. Indicate whether the means of transport you will use to transfer the imported goods whose final destination is outside the Border or Border Region have tracking systems. You must answer as appropriate.
16.6. Indicate whether you have an electronic corporate control system for your operations. You must answer as appropriate.
16.7. Describe the operation of the SECIIT: You must attach a flowchart describing the operation of your SECIIT, which reflects that it complies with what is provided in Section II of Annex 24 and with the guidelines issued for this purpose by the AGACE, as well as that the customs authority has permanent and uninterrupted online electronic access, which will be verified by the customs authority during the inspection visit.
16.8. Indicate whether you carry out temporary imports and return goods listed in Annex II, Sections B and D of the IMMEX Decree: You must answer as appropriate.
17.1. Indicate whether you have registration in the company certification scheme under the IVA and IEPS modality in any of its categories: You must answer as appropriate. You must indicate the category, the expiration date, and the number of the authorization letter by which the Registration in the Company Certification Scheme under the IVA and IEPS modality was granted.
17.2 Companies that do not have an IMMEX Program must demonstrate compliance with the following requirements:
17.2.1. Certificate of personnel registered with the IMSS and documentary support for the payment of the three most recent bimesters prior to the certification request, of at least thirty employees. a) You must attach a certificate of at least thirty contributors registered with the IMSS, from the SUA. In order to avoid attaching the entire SUA, the company may attach the first page (where the corporate name and period appear) and the last page (where the total number of employees registered with the IMSS is recorded). b) To present the proof of payment of worker-employer contributions for at least thirty employees from the last bimester prior to the request, you must attach a payment receipt downloaded from the SIPARE or a payment receipt that is consistent with the information from the SUA, referred to in the first paragraph. Those receipts that contain legends stating they have no fiscal or legal effects will not be valid to demonstrate compliance with the requirement.
17.2.2 Indicate whether the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration in accordance with the constitution of the requesting company, are obligated to pay taxes in Mexico and not obligated to pay taxes in Mexico. You must list the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration in accordance with the constitution of the requesting company, whether or not they are obligated to pay taxes in Mexico. To do this, you must take the following into account:
For those not obligated to pay taxes in Mexico, you must take the following into account:
17.2.3. Indicate whether the partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration in accordance with the constitution of the requesting company, declared taxable income before the tax authority for the purposes of the Income Tax (ISR) corresponding to the two fiscal years prior to the request. You must answer as appropriate.
18.1. Indicate whether you have Registration in the Company Certification Scheme in the IVA and IEPS modality in any of its categories. You must answer as appropriate. You must indicate the category, the expiration date, and the number of the authorization letter by which the Registration in the Company Certification Scheme in the IVA and IEPS modality was granted.
18.2. Indicate whether you have authorization under the strategic fiscalized premises regime. You must answer as appropriate. You must indicate the expiration date and the number of the letter by which the authorization under the strategic fiscalized premises regime was granted to you. You must attach a simple copy of the letter by which the concession or authorization to provide services for the handling, storage, and custody of foreign trade goods was granted to you.
18.3. Indicate whether you are subject to a process of cancellation of the authorization of the strategic fiscalized premises regime. You must answer as appropriate.
19.1. Indicate whether you have a valid IMMEX Services Program. You must answer as appropriate.
19.2. Indicate whether you have Registration in the Company Certification Scheme in the IVA and IEPS modality in any of its categories: You must answer as appropriate. You must indicate the category, the expiration date, and the number of the authorization letter by which the Registration in the Company Certification Scheme in the IVA and IEPS modality was granted.
19.3. Indicate whether you have at least one installation for the provision of logistics services and the safeguarding of foreign trade documentation. You must answer as appropriate.
19.4. Indicate whether you participate directly in the handling of goods and cargo management, using your own transport, distribution centers, warehouses, and/or consolidation. You must answer as appropriate.
19.4.1. Indicate whether you have third parties for the provision of customs, storage, transfer, and/or distribution services of foreign trade goods, which must have Registration in the Company Certification Scheme in the Certified Commercial Partner modality, in any of its categories or CTPAT, granted by CBP. You must answer as appropriate. When the requesting company has third parties for the provision of customs, storage, transfer, and/or distribution services of foreign trade goods, in addition, you must indicate, and if applicable, attach the following:
Companies with Registration in the Company Certification Scheme in the Authorized Economic Operator modality, Logistics Outsourcing category, that request their registration in the SECIIT category, must comply with the requirements established in rule 7.1.4., second paragraph, Section D, with the exception of what is stated in fractions III and IV, exclusively with the catalogs and modules of Section II of Annex 24, indicated in the guidelines issued for such purposes by the AGACE, which will be made known on the SAT Portal; and have carried out at least 50% of the value of their foreign trade operations within the last twelve months, counted from the date of submission of their request, with companies that have valid registration in the SECIIT category.
20.1. Companies that request jointly with the Registration in the Company Certification Scheme in the Authorized Economic Operator modality in any of its categories, and the Registration in the Company Certification Scheme in the Certified Commercial Partner modality, Land Auto Transporter category, must comply, in addition to what is stated in rules 7.1.1. and 7.1.4., with what is provided in the fourth, fifth, sixth, and seventh paragraphs of rule 7.1.4., as follows:
20.1.1. You must indicate whether you request Registration in the Company Certification Scheme in the Authorized Economic Operator modality in any of its categories or, if applicable, indicate whether you have registration in any of said categories, filling in items a), b), and c).
20.1.2. Indicate whether you have your own means of transport for the transfer of foreign trade goods. You must answer as appropriate. Attach the form titled "Profile of the Land Auto Transporter", duly filled out and on magnetic media, for each installation where the handling, storage, and custody of foreign trade goods takes place, by section or by the complete network, as the case may be.
20.1.3. Have the unique permit to operate private freight transport valid, issued by the SICT. You must attach a copy of the document issued by the SICT, with which you certify that you have the valid unique permit to operate private freight transport.
20.1.4. Declaration under oath, regarding the number of own units you have to operate private freight transport. You must attach a free-form letter where you declare under oath the number of own units you have.
20.1.5. Indicate whether the means of transport for the transfer of goods have tracking systems. You must answer as appropriate.
20.1.6. Indicate whether you have CAAT registration. You must answer as appropriate. You must indicate the registration date and the CAAT registration number.
20.2. Companies that request Registration in the Company Certification Scheme in the Authorized Economic Operator modality that are members of the program known as CTPAT, granted by CBP and are located before the RFC, may demonstrate compliance with the requirement established in rule 7.1.4., first paragraph, fraction IV, as follows: Attach the validation report issued in a period not greater than three years from the date the request is presented, through which you certify the applicant as a member of the CBP (CTPAT) Program, with certified-validated status for each of the installations validated by CBP (CTPAT), as well as attach its corresponding simple translation to Spanish.
20.2.1. State whether you authorized CBP (CTPAT) to share information with Mexico, through its CTPAT portal or through the mechanism that the authority of that country defines. You must answer as appropriate. They must comply with the minimum security standards established in the Company Profile format, for which they must deliver the format duly filled out and on magnetic media to the AGACE, as established in the profile filling instructions, only for the installations not validated by CBP (CTPAT). The installations that are validated by CBP (CTPAT) from which the Company Profile is not presented must comply at all times with the minimum security standards established in the Company Profile, as provided in rule 7.2.1., third paragraph, fraction III, third paragraph, and must not be subject to a suspension or cancellation process by CBP (CTPAT).
20.3. Indicate whether, to prove the three-year operating period, you have operated for the last two years as a foreign company under another company with an IMMEX Program under the shelter modality. You must answer as appropriate.
20.4. Contract entered into for a minimum of three years with the company that has the IMMEX Program under the shelter modality. You must attach a copy of the contract entered into, for a minimum of three years, with the company that has the IMMEX Program under the Shelter modality.
21.1 Certified Commercial Partner Modality, Land Auto Transporter Category. Companies that aspire to obtain certification under the Certified Commercial Partner modality in the Land Auto Transporter category must comply with the requirements referred to in rule 7.1.1., with the exception of what is established in fractions VIII, X, XI, and XIV; as well as demonstrate compliance with the requirement referred to in rule 7.1.4., first paragraph, fraction I; and with the minimum security standards referred to in article 100-A, fraction VII of the Law, as follows: Attach the form titled "Profile of the Land Auto Transporter", duly filled out and on magnetic media, for each installation where the handling, storage, and custody of foreign trade goods takes place, by section or by the complete network, as the case may be.
21.2. You must indicate whether you carry out federal auto transport operations. You must answer as appropriate. You must attach the form titled "Profile of the Land Auto Transporter", duly filled out and on magnetic media, complying with the minimum security standards established in the cited format.
21.3. Indicate whether you have at least two years of experience in providing auto transport services for goods. You must answer as appropriate.
21.4. Have the valid permit issued by the SICT to provide the federal auto transport service for freight. You must attach a copy of the document issued by the SICT with which you certify that you have the valid permit to provide the federal auto transport service for freight.
21.5. Declaration under oath, regarding the number of own or leased units you use to provide the service. You must attach a free-form letter where you declare under oath the number of units you have and indicate how many are own and how many are leased. In the case of leased units, you must attach the contract with which you certify the leased units.
21.6. Indicate whether the means of transport you use for the transfer of imported goods have a tracking system. You must answer as appropriate.
21.7. Indicate whether you have CAAT registration. You must answer as appropriate. You must indicate the registration date and the CAAT registration number.
22.1. Indicate whether you authorized CBP (CTPAT) to share information with Mexico, through its CTPAT portal or through the mechanism that the authority of that country defines. You must answer as appropriate.
22.2. Indicate whether the installations that have CBP (CTPAT) certification and from which the Land Auto Transporter Profile must not be presented, comply with the minimum security standards. You must answer as appropriate.
22.3. Indicate whether you are subject to a suspension or cancellation process by CBP (CTPAT). You must answer as appropriate. You must attach the form titled "Profile of the Land Auto Transporter" and on magnetic media only for the installations not validated by CBP (CTPAT).
Thursday, August 3, 2023 OFFICIAL GAZETTE 433
23.1. That its representatives are up to date in the fulfillment of their tax obligations, for which it will indicate the name of each of its representatives, their RFC and whether they are up to date in the fulfillment of their tax obligations. It must indicate the name and RFC of its representatives and whether they are up to date in the fulfillment of their tax obligations.
23.2. Indicate whether the customs license is active. It must answer what corresponds.
23.3. Indicate whether as of the date of presentation the customs license is subject to a process of suspension, cancellation, extinction, disqualification or voluntary suspension, referred to in articles 164, 165 and 166 of the Law. It must answer what corresponds.
23.4. Indicate whether the customs license has been suspended, cancelled, extinguished or disqualified in the three years prior to the presentation of its application. It must answer what corresponds.
23.5. In the event that one or more societies have been incorporated and/or constituted, in accordance with fraction II of article 163 of the Law, repealed by Decree published in the DOF on June 25, 2018, these must be up to date in the fulfillment of their tax obligations, for which it must indicate the name and RFC of said societies. It must indicate the full name, RFC and customs where said societies act.
23.6. Additional data of the customs broker. It must indicate the customs of assignment, authorized additional customs, number of workers registered with the IMSS as of the date of its application, number of workers registered through a service provision contract and declare that the license has a minimum of two years of experience in the presentation of customs services.
23.7. Describe the additional services to customs management that the customs broker provides (Add the lines that are necessary). It must describe the services provided by the customs broker, in addition to customs management.
23.8. Data of the agency's facilities. It must indicate the name and/or denomination, address and type of installation that belong to the license of the applying customs broker, for such purposes they may add the rows that are necessary.
24.1. Have the valid concession or permit issued by the SICT to provide the freight railway transport service. It must attach a copy of the document issued by the SICT, with which it accredits that it has the valid concession or permit to provide the freight railway transport service.
24.2. Indicate whether it has own units, leased under loan for use or another legal figure with which it accredits the possession of the same (tractive equipment) that it uses to provide the service: It must attach a free-form statement where it declares under oath the quantity of units it has and indicate how many are own and how many are leased. In the case of leased units, it must attach the contract with which it accredits the leased units.
24.3. Indicate whether the means of transport for the transfer of merchandise have tracking systems in accordance with what is established in the form named Railway Carrier Profile. It must answer what corresponds.
434 OFFICIAL GAZETTE Thursday, August 3, 2023
25.1. It must indicate the name and/or denomination of each Industrial Park for which registration is requested and that belong and operate under the same RFC of the corporate group. The hosted installations can be industrial plants, warehouses, distribution centers, etc. and must carry out foreign trade operations.
25.2. Have the Environmental Impact Manifestation. It must attach the document issued by SEMARNAT on the environmental impact in accordance with standard NMX-R-046-SCFI-2015.
26.1. Indicate whether at the time of presentation of its application it has the Fiscalized Premises authorization. It must answer what corresponds. It must indicate the expiration date and official number of the authorization as a fiscalized premise. It must attach a simple copy of the official document through which the authorization for the elaboration, transformation or repair in a fiscalized premise was granted.
26.2. Indicate whether at the time of presentation of its application it is subject to a process of cancellation of the Fiscalized Premises authorization. It must answer what corresponds.
27.1. Indicate who owns the aircraft in which the transport of documents and merchandise is carried out. It must indicate whether the aircraft in which the transport of documents and merchandise is carried out are own, or belong to its subsidiary, affiliate or parent company. It must indicate the name of the owner of the aircraft in which the transport of documents and merchandise is carried out. It must attach a service contract, with a minimum validity of five years and not less than one year as of the date of its application, celebrated directly or through its parent companies, affiliates or subsidiaries, with a concessionaire or permit holder duly authorized by the SICT, through which it makes available for dedicated use of the activities of the courier or parcel company at least 30 aircraft and which provides regular frequencies to the airports where said company carries out the dispatch of documents or merchandise. Likewise, it must attach a document issued by the General Directorate of Civil Aeronautics of the SICT in favor of the concessionaire or permit holder with which it accredits that they have authorized or registered the air routes or airways within the national airspace.
27.2. Indicate who operates the transport of aircraft. It must indicate who operates the transport of aircraft if it is the applying subsidiary, affiliate or parent company. Attach a document issued by the General Directorate of Civil Aeronautics of the SICT with which it accredits that it has the registration of air routes or airways within the national airspace.
27.3. Indicate whether it has the concession or authorization to provide the services of handling, storage and custody of foreign trade merchandise in accordance with articles 14 and 14-A of the Law. It must answer what corresponds. It must indicate the expiration and the official number with which the concession or authorization to provide the services of handling, storage and custody of foreign trade merchandise in accordance with articles 14 and 14-A of the Law was granted.
27.4. Indicate whether as of the date of presentation of its application it has a minimum investment in fixed assets by an amount equivalent in national currency to 1,000,000 dollars. It must answer what corresponds. It must attach the documentation with which it accredits that as of the date of presentation of its application it has a minimum investment in fixed assets by an amount equivalent in national currency to 1,000,000 dollars.
27.5. Indicate whether for the purposes of this sub-sector it is accredited in a group. It must answer what corresponds. It must indicate the name of the companies that are part of the group.
Thursday, August 3, 2023 OFFICIAL GAZETTE 435
27.6. Indicate the name of the companies that are part of the group that has the aircraft. It must indicate the name and RFC of the companies that are part of the group that have the aircraft. It must attach the documentation with which it accredits that they have aircraft for the transport of documents and merchandise, through a service contract, celebrated directly or through an operating company that is part of the same group, which has a concession or permit authorized by the SICT, through which it makes available for exclusive use of the courier and parcel activities at least 3 aircraft and provides regular frequencies to the airports where the courier and parcel companies carry out the dispatch of the documents or merchandise. Likewise, it must attach a permit from the SICT, issued in favor of the company that is part of the group.
27.7. Indicate the name of the companies that are part of the group, which operate the transport of the aircraft indicated in the previous fraction, have their air routes or airways authorized or registered within the national airspace before the General Directorate of Civil Aeronautics of the SICT. It must indicate the name and RFC of the companies that are part of the group, which operate the transport of the aircraft. It must attach a document issued by the General Directorate of Civil Aeronautics of the SICT, in favor of any of the companies that are part of the group with which it accredits that they have authorized or registered the air routes or airways within the national airspace.
27.8. Indicate the name of the companies that are part of the group, which have the concession or authorization to provide the services of handling, storage and custody of foreign trade merchandise in accordance with articles 14 and 14-A of the Law. It must indicate the name and RFC of the companies that are part of the group, which have the concession or authorization to provide the services of handling, storage and custody of foreign trade merchandise in accordance with articles 14 and 14-A of the Law. It must indicate the expiration and the official number with which the concession or authorization to provide the services of handling, storage and custody of foreign trade merchandise in accordance with articles 14 and 14-A of the Law was granted. It must answer what corresponds.
28.1. Indicate whether at the time of presentation of its application it has the authorization to provide the service of storage of merchandise in the fiscal deposit regime. It must answer what corresponds. It must indicate the expiration date and the official number of the authorization to provide the service of storage of merchandise in the fiscal deposit regime. It must attach a simple copy of the official document through which the authorization to provide the service of storage of merchandise in the fiscal deposit regime was granted.
28.2. Indicate whether at the time of presentation of its application it is subject to a process of cancellation of the authorization to provide the service of storage of merchandise in the fiscal deposit regime. It must answer what corresponds.
Mutual recognition for the Authorized Economic Operator and Certified Business Partner modalities. Indicate whether they authorize or not the obligated subject named SAT, through the AGACE, to share, disseminate or distribute with other national or foreign authorities the personal data and other information of the company that they represent, and that is generated during the course in which it is registered in the Registration in the Business Certification Scheme.
List of Certified Business Partners. With the aim of creating safer supply chains, a list will be established with the companies that have obtained certification as Certified Business Partner, which will be published on the SAT Portal and will include the general data that the company authorizes, as well as the status of its certification, which can be consulted by the companies that have obtained their registration in the Registration in the Business Certification Scheme. Indicate the general data that they authorize to publish.
Classification of information. Indicate whether the information provided, during the procedure for Registration in the Business Certification Scheme, is classified by the company as public or confidential. ...
436 OFFICIAL GAZETTE Thursday, August 3, 2023
F3.3. Procedure Instruction to obtain Registration in the Business Certification Scheme in the Authorized Economic Operator modality under the sub-sectors of Import and/or Export; Holding Company; Aircraft; SECIIT; Textile, Strategic Fiscalized Premises and Logistics Outsourcing.
Who presents it? Legal entities.
Where is it presented? Before the AGACE:
What document is obtained upon completion of the procedure? Official response to the application.
When is it presented? At any time.
Requirements:
Declare: a) Name, denomination or corporate name and address of all clients and suppliers abroad, with whom they carried out foreign trade operations during the last twelve months, directly or indirectly linked with the customs regime with which the Registration in the Business Certification Scheme is requested. b) Name and RFC of all their suppliers of inputs acquired in national territory, linked to the process under the regime they are applying for, of the last twelve months, prior to the date of presentation of the application.
Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of presentation of the application, referred to in article 40, subsection m) of the LFD.
Certificates of personnel registered with the IMSS, of the SUA of the last bimonthly period prior to the date of presentation of the application.
Profile of the Company or Profile of the Strategic Fiscalized Premises form as appropriate, for each of the installations, where foreign trade operations are carried out and on magnetic media.
Documentation with which it is accredited that the company has the legal use or enjoyment of the real estate or real estate where the productive processes or the provision of services are carried out, as appropriate, of at least one year of validity from the date of presentation of the application.
Documentation with which it is accredited that it has carried out in the semester immediately preceding that in which they enter their application, imports by a value in customs not less than $300,000,000.00.
Those interested in obtaining Registration in the Business Certification Scheme, sub-sector Importer and/or Exporter, additionally must attach the documentation with which it is accredited that they have carried out foreign trade operations during the last two years prior to their application.
Those interested in obtaining Registration in the Business Certification Scheme, sub-sector Holding Company, additionally must attach: a) Document issued by the SE, through which it is accredited that they have been designated as holding companies to integrate the manufacturing or maquila operations of two or more controlled societies, with respect to which the holding company participates directly or indirectly in their administration, control or capital, when any of the controlled has such direct or indirect participation on the other controlled and the holding company, or when a third company, whether resident in national territory or abroad, participates directly or indirectly in the administration, control or in the capital of both the holding company and the controlled societies. b) List of controlled societies, indicating their shareholding, their denomination or corporate name, tax address, RFC and the amount of imports and exports carried out by each of the societies. c) Diagram of the shareholding and corporate structure, as well as certified copy of the public deeds, in which the shareholding participation of the holding company and of the controlled societies is stated.
Thursday, August 3, 2023 OFFICIAL GAZETTE 437
a) Valid IMMEX Program Authorization granted by the SE and Registration in the Business Certification Scheme in the IVA and IEPS modality, in any of its sectors.
b) Certified copy of the permit from the General Directorate of Civil Aeronautics of the SICT, for the establishment of aircraft workshops, when companies carry out such processes.
a) Copy of the valid IMMEX Program and hold Registration in the Business Certification Scheme, IVA and IEPS modality, in sectors AA or AAA.
b) The favorable opinion issued by the authorized Civil Association, Chambers or Confederation in accordance with rule 7.1.9., which certifies compliance with what is provided in the Guidelines of the Electronic System for the Control of Inventories of Temporary Imports, in accordance with rule 7.1.10.
c) To comply with what is stated in point 16.4, the following must be indicated according to the selected option or options:
i) Certificate of all personnel registered with the IMSS issued by the SUA, in which it can be visualized that it has at least 1,000 workers registered with the IMSS.
ii) Attach documents that certify that it has fixed assets of machinery and equipment for an amount equivalent in national currency to 30,000,000 dollars.
iii) That the company trades on recognized markets in terms of article 16-C of the CFF.
In the case that the requesting company does not trade on the stock exchange, it may present the documentation that demonstrates that at least 51% of its shares with voting rights are owned directly or indirectly by a company that trades on recognized markets.
d) Documentation that certifies that the means of transport that will be used for the transfer of import goods whose final destination is outside the border or border region, have tracking systems.
e) Flowchart describing the operation of its SECIIT, which reflects that it complies with what is provided in section II of Annex 24 and with the guidelines issued to that effect by the AGACE, as well as that the customs authority has permanent and uninterrupted electronic online access, which will be verified by the customs authority during the inspection visit.
a) Certificate of personnel registered with the IMSS, from the SUA, or in order to avoid attaching the entire SUA, the first page (where the corporate name and period appear) and the last page (where the total number of employees registered with the IMSS is recorded) may be attached.
b) Proof of payment of worker-employer contributions for at least thirty employees from the last bimester prior to the application; proof of payment downloaded from the SIPARE or proof of payment that is consistent with the information from the SUA, referred to in the first paragraph, must be attached. Those proofs that contain legends stating that they have no fiscal or legal effects will not be valid to certify the requirement.
c) List of partners, shareholders, as applicable, legal representative with authority for acts of dominion, and members of the administration in accordance with the constitution of the requesting company, whether or not they are obligated to pay taxes in Mexico. In case they are not obligated to pay taxes, the following must be attached:
i) List of Partners, Shareholders or Associates, residents abroad of legal entities resident in Mexico that opt not to register in the RFC. (Official Form 96 "List of Partners, Shareholders or Associates residents abroad", of Annex 1 of the RMF).
ii) Legal representative, sole administrator and/or members of the board of directors, in an enumerative, but not exhaustive manner, documents such as, Opinion of compliance with tax obligations with the legend No tax obligations, certificate of residence for tax purposes of the country where it pays taxes, tax declarations of the country where they are obligated to pay taxes, etc.
438 OFFICIAL GAZETTE Thursday, August 3, 2023
Interested parties seeking Registration in the Business Certification Scheme, Strategic Fiscalized Premises sector, must attach a simple copy of the letter by which the concession or authorization to provide services for handling, storage, and custody of foreign trade goods was granted.
Interested parties seeking Registration in the Business Certification Scheme, Logistics Outsourcing sector, who only carry out the handling of goods on behalf of third parties, must attach the following:
a) Documentation that certifies that the company has the legal use or enjoyment of the property or properties where it will provide the logistics services and custody of foreign trade documentation, with a validity of at least one year from the date of submission of the application.
b) Documentation that certifies the commercial relationship, in case of having third parties for the provision of customs, storage, transfer and/or distribution services of foreign trade goods.
a) Validation report issued in a period not greater than three years from the date the application is presented, through which it certifies the applicant as a member of the CBP (CTPAT) program, with certified-validated status, for each of the facilities validated by CBP (CTPAT), and its corresponding simple translation into Spanish.
b) Documentation that certifies the minimum security standards established in the Company Profile format, for which the format must be delivered to the AGACE duly filled out and on magnetic media, in accordance with what is established in the profile filling instruction, only for the facilities not validated by CBP (CTPAT).
Conditions:
Comply with the obligation to retain and pay the ISR of workers.
For the case of numeral 11, it must comply with what is stated in section II of Annex 24 and with the guidelines issued to that effect by the AGACE.
Additional Information:
In the case that the customs authority detects the lack of any requirement, it will request the applicant only once, who will have a period of fifteen days counted from the day following the notification taking effect, to address the request; otherwise, the application will be considered rejected.
The AGACE will issue the response letter to the application, in a period not greater than one hundred twenty days, counted from when all established requirements are fully covered, as applicable. After said period has passed, without a resolution having been made, it will be understood that the resolution is favorable.
Companies with Registration in the Business Certification Scheme in the Authorized Economic Operator modality, Logistics Outsourcing sector, that request their registration in the SECIIT sector, must comply with the requirements established in rule 7.1.4., second paragraph, Section D, with the exception of what is stated in fractions III and IV, exclusively with the catalogs and modules of section II of Annex 24, indicated in the guidelines that for such purposes are issued by the AGACE, which will be made known on the SAT Portal; and have carried out at least 50% of the value of their foreign trade operations within the last twelve months, counted from the date of submission of their application, with companies that have valid registration in the SECIIT sector.
When the taxpayer, in accordance with rule 1.2.2., presents any documentation to complement their application for Registration in the Business Certification Scheme, they must exhibit the same on magnetic media.
Applicable Legal Provisions:
Articles 100-A and 135-A of the Law, 16-C of the CFF, 40, subsection m) of the LFD, rules 1.2.2., 7.1.1., 7.1.4., 7.1.6., 7.1.7., 7.1.9., 7.1.10. and Annex 24 of the RGCE.
Thursday, August 3, 2023 OFFICIAL GAZETTE 439
F3.4. Procedure Instructions to obtain Registration in the Business Certification Scheme, Certified Commercial Partner modality, sectors: terrestrial auto-transporter, customs broker, railway transport, industrial parks, fiscalized premises, courier and parcel services, and general warehouse.
Who presents it? Natural or legal persons.
Where is it presented? Before the AGACE.
Through Digital Window, for the sectors of Terrestrial Auto-transporter, Customs Broker, Railway Transport, Industrial Parks, Fiscalized Premises, and Courier and Parcel Services.
In the official records office, this application and attached documents can be sent, or you can send your notice via SEPOMEX or using the services of courier companies. For the General Warehouse sector.
What document is obtained upon completing the procedure? Response letter to the application for Registration in the Business Certification Scheme.
When is it presented? At any time.
Requirements:
a) Documentation that certifies that it carries out federal terrestrial auto-transport operations.
b) Form known as Profile of the Terrestrial Auto-transporter duly filled out and on magnetic media, with which it certifies compliance with the minimum security standards established in the cited format.
c) Documentation that certifies registration in the CAAT, in accordance with rule 2.4.5., in case of being carrier companies.
d) Transmit:
i) Documentation that certifies two years as a minimum of experience in the provision of freight auto-transport services.
ii) Document that certifies that it has the valid permit, issued by the SICT, to provide the federal freight auto-transport service.
iii) Declaration under oath, regarding the number of owned or leased units, that it uses to provide the service.
e) Prove that the means of transport that will be used for the transfer of goods have tracking systems in accordance with what is established in the form known as Profile of the Terrestrial Auto-transporter.
f) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
a) Validation report that certifies the applicant as a member of the CBP (CTPAT) program, with certified-validated status.
b) Documentation that certifies that they have been authorized to share information with Mexico on its CBP (CTPAT) portal.
440 OFFICIAL GAZETTE Thursday, August 3, 2023
c) Documentation that certifies that they comply with the minimum security standards established in the Profile of the Terrestrial Auto-transporter format, for which the format must be delivered to the AGACE duly filled out and on magnetic media, in accordance with what is established in the profile filling instruction, only for the facilities not validated by CBP (CTPAT).
d) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
Additionally, the facilities that are validated by CTPAT from which the company profile is not presented, must comply with the minimum security standards established in the Company Profile.
a) Declare:
i) Name of the persons who have served as their agents and the customs offices before which they acted.
ii) Describe the additional services to customs management that the customs broker provides.
iii) Indicate all facilities that belong to the patent of the requesting customs broker.
b) Certify:
i) That all their agents are up to date in the fulfillment of tax obligations.
ii) That the customs patent is active and is not subject to a process of suspension, cancellation, extinction or voluntary suspension referred to in articles 164, 165 and 166 of the Law, nor has it been suspended or cancelled in the three years prior to the year in which they request registration in the registry.
iii) That they have promoted on behalf of others the clearance of goods in the two years prior to the year in which they request registration in the business certification scheme under the Certified Commercial Partner modality, customs broker sector.
iv) In case one or more societies have been incorporated and/or constituted, in accordance with fraction II of article 163 of the Law, repealed by Decree published in the DOF on June 25, 2018, these must have presented the ISR declaration corresponding to the last fiscal year for which the society or societies are obligated on the date of submission of the application referred to in this fraction.
c) Form known as Profile of the Customs Broker duly filled out and on magnetic media, with which it certifies compliance with the minimum security standards established in the cited format.
d) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
a) Form known as Profile of the Railway Transporter duly filled out and on magnetic media, for each installation where handling, storage and custody of foreign trade goods is carried out, by section or by the complete network as applicable.
b) Copy of the document that certifies that it has the valid concession or permit, issued by the SICT, to provide the freight railway transport service.
c) Documentation that certifies that it has owned or leased units (tractive equipment), in usufruct or other legal figure with which it certifies possession of the same (tractive equipment), that it uses to provide the service.
d) Documentation that certifies that the means of transport that will be used for the transfer of goods have tracking systems in accordance with what is established in the form known as Profile of the Railway Transporter.
Thursday, August 3, 2023 OFFICIAL GAZETTE 441
e) Documentation that certifies two years as a minimum of experience in the provision of freight transport services by railway, prior to the year in which they request Registration in the Business Certification Scheme.
f) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
a) Form known as Profile of the Industrial Park duly filled out and on magnetic media, for each Industrial Park.
b) Environmental impact statement.
c) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
Interested parties seeking Registration in the Business Certification Scheme, in the Certified Commercial Partner modality, Fiscalized Premises sector, in addition to what is established in rules 7.1.1. with the exception of fractions VIII, X, XI, and 7.1.4 first paragraph, fraction I, must attach the form known as Profile of the Fiscalized Premises duly filled out and on magnetic media, for each authorized installation, as well as the payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
Interested parties seeking Registration in the Business Certification Scheme, in the Certified Commercial Partner modality, Courier and Parcel Services sector, in addition to what is established in rules 7.1.1. and 7.1.4, fractions I and II, must:
a) Transmit the document(s), with which it certifies that the aircraft in which they transport documents and goods are owned by the courier and parcel services company or by any of its national or foreign affiliates, subsidiaries or parent companies.
In its case, the service contract with a minimum validity of five years, and not less than one year on the date of its application, celebrated directly or through its parent companies, affiliates or subsidiaries, with a concessionaire or permit holder duly authorized by the SICT, through which it makes available for dedicated use of the activities of the courier or parcel services company at least 30 aircraft and that provides regular frequencies to the airports where said company carries out the clearance of documents or goods.
b) Certify that they have:
i) Registration of air routes or airways within national airspace before the General Directorate of Civil Aeronautics of the SICT.
ii) Concession or authorization to provide services for handling, storage and custody of foreign trade goods in accordance with articles 14 and 14-A of the Law.
iii) With a minimum investment in fixed assets for an amount equivalent in national currency to 1,000,000 dollars on the date of submission of the application, according to the financial statements report for tax purposes, corresponding to the last fiscal year for which it is obligated on the date of the submission of the company registration application.
c) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
a) Declare:
i) Corporate name, tax address and RFC of each of the companies that make up the group.
442 OFFICIAL GAZETTE Thursday, August 3, 2023
b) Accreditation:
i) That they have aircraft for the transportation of documents and merchandise, through a service contract, concluded directly or through an operating company that is part of the same group, which holds a concession or permit authorized by the SICT, under which they make available for exclusive use in messenger and package activities at least three aircraft and provide regular frequencies to the airports where messenger and package companies carry out the dispatch of documents or merchandise.
ii) That they have, directly or through a company that is part of the same group, a concession or authorization to provide services for the handling, storage, and custody of foreign trade merchandise in accordance with Articles 14 and 14-A of the Law.
c) Attach a diagram of the shareholding and corporate structure, as well as copies of the public deeds, showing the shareholding participation of the applicant companies.
d) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in Article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
a) Attach the form titled Profile of the General Warehouse Deposit, duly completed and on magnetic media, for each location, installation, warehouse, or branch that the general warehouse deposit determines, provided that they have authorization to provide the service of storing merchandise destined for the tax deposit regime.
b) Payment of the fee made through the electronic e5cinco scheme, corresponding to the date of submission of the application, referred to in Article 40, subsection m) of the LFD, in relation to Annex 19 of the RMF in force on the date of submission of the registration application.
Conditions:
That they participate in the handling, storage, custody, and transport of foreign trade merchandise.
For the cases of items 6 and 9 of the Requirements Section, valid authorization must be held and not be subject to a cancellation process.
Additional Information:
In the event that the customs authority detects the lack of any requirement, it will request the applicant only once, and will grant a period of fifteen days counted from the day following the notification taking effect, for the applicant to address the request; otherwise, the application shall be considered withdrawn.
The AGACE will issue the response letter to the application within a period not exceeding one hundred twenty days, counted from the date all established requirements are fully met, as applicable. If this period elapses without a resolution having been issued, the resolution shall be understood to be favorable.
When the taxpayer, in accordance with rule 1.2.2., presents any documentation to complement their Registration Application in the Enterprise Certification Scheme, they must exhibit the same on magnetic media.
Applicable Legal Provisions:
Articles 14, 14-A, 100-A, 159, 163, 164, 165, and 166 of the Law, Article 40 subsection m) of the LFD, Rules 1.2.2., 2.4.5., 7.1.1, 7.1.4., 7.1.5., 7.1.6., 7.1.7., 7.2.1., 7.2.2., and 7.2.3. of the RGCE, and Annex 19 of the RMF.
III. ...
...
Respectfully.
Mexico City, July 14, 2023.- In substitution for the absence of the Head of the Tax Administration Service, based on Article 4, first paragraph of the Internal Regulations of the Tax Administration Service, the General Legal Administrator, Lic. Ricardo Carrasco Varona, signs.-
Rubric.
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.