Vantario

Insight

What CTPAT §3.9 actually requires of your suppliers

July 27, 2026

The business partner standard is one of the least specific requirements in the Minimum Security Criteria, and one of the most consequential. Here is what it asks for, and where most programs are thin.

CTPAT Minimum Security Criteria section 3.9 requires partners to maintain a documented social compliance program that addresses how the company ensures goods imported into the United States were not mined, produced or manufactured, wholly or in part, with prohibited forms of labor.

That sentence carries more weight than its length suggests. Three phrases do the work.

"Documented"

Not "has a policy." Not "believes its suppliers comply." A written program that can be produced on request and that describes what the company actually does.

In practice this means a procedure document: who owns supplier screening, what is checked, how often, what happens when a supplier is flagged, and where the evidence lives. Most companies have the intent and not the document.

"Wholly or in part"

This is the phrase that extends the obligation past your direct supplier. A component manufactured by your tier-1 supplier using material from a tier-3 source is still "in part" — and the standard does not stop at the company you send purchase orders to.

This is where most programs are thinnest. Annual supplier questionnaires typically reach tier 1. The exposure that gets shipments detained usually lives further upstream, in raw material sourcing that nobody has mapped.

"Prohibited forms of labor"

Not only child labor. The category covers forced labor, indentured labor, bonded and debt-bonded labor, prison or convict labor, and labor obtained through human trafficking or coercion.

This is the single most common gap. In practice, the typical supplier attestation letter addresses child labor and nothing else — leaving four or five prohibited categories unmentioned in the document a company is relying on as evidence of due diligence.

How this connects to OEA

Mexico's Operador Económico Autorizado program implements the same World Customs Organization SAFE Framework standard. Its business partner requirement appears in Anexo 1 of the security profile, Estándar 4 — Socios Comerciales.

The two regimes are substantively equivalent, which is convenient and also a trap. Companies certified under both sometimes assume that satisfying one satisfies the other. In enforcement terms they behave very differently: OEA is oriented toward fiscal and administrative benefit, while CBP is oriented toward enforcement. A flexible posture from one authority offers no protection from the other.

What a defensible program looks like

Practitioners consistently describe the same escalating sequence:

StepWhat it establishes
Contract clauseA prohibition on prohibited labor with defined consequences for breach. Usually the first thing an authority asks to see.
ScreeningChecking suppliers against restricted-entity lists, adverse media, and litigation records.
Signed attestationA binding declaration from the supplier's legal representative, renewed on a defined cycle.
AuditPhysical verification where risk justifies it. The most probative evidence and the least scalable.

The purpose of all four is not to discover forced labor. It is to be able to demonstrate that you looked — which is what the standard actually asks of you, and what an authority weighs when something goes wrong.

The gap nobody closes

The attestation is annual. Restricted-entity lists are not. A supplier who was clean when the letter was signed can be listed four months later, and an annual questionnaire has no mechanism to notice.

That interval between certifications is where most programs have nothing at all — and it is the period an authority will ask about if a shipment is held.

Check a letter

Paste or upload one of your supplier attestation letters and see which of the ten elements it covers. Free, no signup, English or Spanish. Scanned PDFs work.

Run a free check