Insights
Practical notes on the CTPAT and OEA business partner standard, UFLPA documentation, and what holds up when an authority asks.
Most writing about supplier due diligence describes what the regulation says. This is about what practitioners actually do — which is frequently narrower, and occasionally more fragile, than the rules on paper suggest.
The recurring theme is documentation. Under the Uyghur Forced Labor Prevention Act the burden of proof runs backwards: an importer must demonstrate that goods were not made with prohibited labour, usually within thirty days of a shipment being detained. CTPAT Minimum Security Criteria §3.9 and its Mexican equivalent — OEA, Anexo 1, Estándar 4 — require a documented programme covering business partners. Both are satisfied with paper, and the quality of that paper varies enormously.
These pieces draw on published standards and on conversations with people who run CTPAT and OEA programmes at manufacturers operating across the US–Mexico border. Where practice diverges from the regulation, that divergence is reported rather than smoothed over.
A real UFLPA detention: four containers, a supplier legally barred from providing the documentation, and why the exit that saved that cargo no longer exists.
The business partner standard is one of the least specific requirements in the Minimum Security Criteria, and one of the most consequential. Here is what it asks for, and where most programs are thin.
Almost every company subject to CTPAT or OEA collects an annual letter from its suppliers. Almost nobody checks that letter against what the standard actually requires.
The Uyghur Forced Labor Prevention Act reversed the burden of proof. The practical consequence is not that you must prove a negative — it is that you must prove it on a clock that starts when it is already too late to begin.