Photo © jdarius. Illustrative image

Before you hand over your cargo: how to assess the security of warehouses and high-value goods carriers

You can read this article in 9 minutes

A high-value shipment is only as secure as the warehouse, carrier and subcontractors handling it. Licences, insurance, certificates and years of successful cooperation all matter—but none can replace current, practical checks. Here’s how to assess whether a logistics partner still protects your cargo today, not merely whether it passed an audit in the past.

The text you are reading has been translated using an automatic tool, which may lead to certain inaccuracies. Thank you for your understanding.

Key takeaways for vetting high-value cargo partners

  • High-value cargo is defined by more than its invoice value. Criminal appeal, ease of resale and the transport route also influence the risk.
  • A long-standing relationship does not replace due diligence. Changes in ownership, facilities, subcontractors or security providers should trigger a fresh risk assessment.
  • A questionnaire records the safeguards a partner says it has in place. An audit tests whether those safeguards work in practice.
  • TAPA FSR and TSR certifications help structure security requirements, but their scope, location and covered process must be checked.
  • Security due diligence should be ongoing, with scheduled audits and checks on a carrier’s subcontractors.

For high-value goods, electronics, cosmetics, luxury products and fashion items, this responsibility is particularly significant. These products appeal to criminals not only because of their value, but also because they are easy to move, split into smaller quantities and resell. A recognisable brand can make them even more attractive.

That is why high-value cargo should not be identified solely by the amount shown on an invoice. From a risk-management perspective, the product’s appeal to criminals, resale potential, transport route, storage location, seasonality and distribution model all matter.

The essential question is simple: how well do we really know the companies entrusted with our goods?

A long-term relationship is not a security procedure

Many organisations rely on the same argument: “We have worked with this company for ten years and never had a problem.” A strong, long-running relationship is valuable. It builds trust, provides insight into the partner and can contribute to the risk assessment. It should not, however, replace regular verification.

The company selected a decade ago may no longer be the same organisation. Ownership may have changed, or the business may have merged with or been acquired by another company. Its management team, security lead or operating model may also be different. The partner may have moved its warehouse, changed subcontractors, reduced its security staffing, switched monitoring providers or begun using more external carriers.

Do organisations reassess the risk after such changes? Often, they do not. The partner remains on the approved-supplier list because it has been there for years. Documents are refreshed, an insurance policy is submitted, the contract is extended and operations continue. From a security perspective, the key question is whether the current organisation is still the one that was originally assessed.

Trust needs to be verified

Security due diligence should not be a one-off exercise completed before the first contract is signed.

Partner reviews should be conducted regularly, with certain changes automatically prompting a new risk assessment. A change in ownership, warehouse location, key subcontractor, security system or operating model is not merely an administrative update. It can directly affect the level of protection provided to the cargo.

This matters especially when high-value goods are involved. The question should not be, “Do we know this company?” It should be, “Do we know how this company operates today?” Those are two very different questions.

Warehouse cameras are only the starting point

One of the most common mistakes when assessing a warehouse is to focus on whether security measures exist at all. The checklist may look reassuring:

  • Is the site monitored? Yes.
  • Is there an alarm? Yes.
  • Is access controlled? Yes.
  • Is the site fenced? Yes.

On paper, everything may appear to be in order. But the mere presence of a security measure says little about how effective it is.

What matters is how the system performs in real operating conditions. Ask questions such as:

  • Does camera coverage include every critical area, including loading bays and loading points? 
  • How long are recordings retained? 
  • Who can access them? 
  • Is the alarm monitored around the clock, and who responds to an alert outside normal working hours? 
  • How are access cards issued, tracked and recovered? 
  • Are former employees’ access rights removed immediately? 
  • Can temporary workers enter areas where high-value products are stored?

The release process is just as important. The warehouse should know which company is collecting the shipment, which vehicle is expected and who will be driving it. An unplanned change to the driver, registration number or carrier should trigger additional checks—not automatic approval simply because the shipment needs to leave quickly.

A security questionnaire shows what safeguards a partner declares. An audit reveals how security works in reality.

A carrier’s licence and insurance are not enough

The same issue arises when carriers are approved. Checking the company’s licence, insurance and basic corporate details is essential, but for high-risk transport it should be the starting point, not the finish line.

You should understand how the carrier controls access to shipment information, trains drivers, responds to incidents, approves stopping locations and monitors vehicles. It is also important to know who acts when the system raises an alert at three in the morning. Technology alone is not enough if there is no response process behind it.

Subcontracting deserves particular attention. The company that has been thoroughly vetted may not be the one physically carrying out the transport. Establish whether the carrier can pass the job to another company, under what conditions, who checks those subcontractors and whether the customer’s security requirements apply to every party involved in the movement.

If we expect a specific standard from our direct partner, that standard should travel with the cargo through the rest of the supply chain.

Certification should not be the end of the vetting process

Standards and certifications such as TAPA FSR for facilities and TAPA TSR for transport can be valuable components of a cargo-security programme. They help organise requirements and give companies and their partners a common benchmark.

Even so, the process should not be reduced to one question: “Does the company hold a certificate?” Check what activities the certification covers, which location it applies to and whether it relates to the specific process being entrusted with the product. Due diligence should reflect the actual risk, rather than become another box ticked on a supplier form.

A pre-contract audit is not enough

Suppose a warehouse underwent a thorough audit before cooperation began. All requirements were met, procedures worked properly and the infrastructure matched the level of risk.

Five years later, the relationship is still active. Has anyone returned to inspect the site? Does the camera system still cover the same areas? Has the operating model changed? Has the number of temporary workers increased several times over? Is access control managed in the same way? Has the security provider changed? Are new subcontractors involved?

Security is not a condition achieved once and maintained forever. It is an ongoing process. A mature partner-management model should therefore include initial qualification, periodic audits, updated risk assessments and renewed checks after material changes.

The greatest risk may be assuming you know your partner

Paradoxically, a long relationship can sometimes reduce vigilance. The longer we work with a partner, the easier it becomes to treat certain things as guaranteed.

You often hear comments such as, “That’s how we have always done it,” “Nothing has ever happened before” or “They are a trusted partner.”

In security, statements like these should lead to more questions, not end the discussion.

A clean incident record is not a guarantee of future safety. Companies, people, technology, processes and criminal methods all change. Security arrangements must change with them.

Owners of high-value goods should therefore assess logistics partners on more than price, service quality and delivery performance – security should remain a permanent part of supplier relationship management.

This is not about distrusting partners. Quite the opposite: it is about building a model in which trust is repeatedly confirmed by evidence. The most important question is not, “Did we vet this partner in the past?” It is, “Would we approve this partner again today?”

This article is part of an open series examining the growing problem of cargo theft and security in the transport sector. The series explores how criminal groups operate and how companies can protect their goods and drivers. Find all articles in the series under the hashtag #TransportSecurityInsights.

Tags:

Also read