We stand up the program that keeps your imports and exports defensible: written procedures, denied party screening, recordkeeping, and audit response, so your company can prove
it met its legal obligations before a regulator ever asks.
Trade compliance management is the program of policies, controls, and records that proves your company follows U.S. import and export law, from reasonable care on entries and guidance on trade agreement eligibility to screening every party you trade with.
CargoTrans writes those controls into procedures your team can actually run, files the entries against them through our licensed customs broker desk, and provides consulting support on the tougher classification and customs valuation calls, so policy and practice match, one of the services that keep your program audit-ready alongside our technology and visibility reporting.
The program spans both directions of the flow: it governs how you clear inbound goods and how you document and license your outbound import and export operations, and it exists to mitigate the real cost of getting either wrong: penalties, shipment delays, and reputational damage.
5 yrs
Record retention
$10K+
Per-violation penalty
Daily
Denied-party list updates
Free Consultation
Talk to a Compliance Lead
Quick 30-min program review. No obligation.
We reply within 1 business day · Your data stays private.
Why Choose CargoTrans for Trade Compliance Management
Our compliance team sits next to the brokers who file your entries, so your written procedures match what actually gets declared to CBP.
We screen every party against OFAC, BIS, and other restricted lists on each transaction, not once at onboarding when relationships and lists both change.
We build the manual to your specific commodities and trade lanes, so it reflects your real ECCNs and ports rather than a generic template.
When a CF-28 or an audit lands, the same team that built your records drafts the response, so nothing gets explained by a stranger.
Our Process
How We Build Your Compliance Program
01
Gap Assessment
Review current procedures, records, and screening against the law.
02
Risk Profiling
Rank exposure by commodity, trade lane, and counterparty.
03
Write the Controls
Draft procedures and the compliance manual to your operations.
04
Deploy and Screen
Turn on screening, recordkeeping, and sign-off workflows.
05
Monitor and Train
Run internal audits, retrain staff, and update as rules change.
The difference between a routine audit and a penalty is whether your file already exists. A living compliance program builds that file before anyone asks to see it.
CargoTrans turns compliance from a scramble into a record.
Free 30-minute program review with a compliance lead
Denied party screening across all restricted lists
Import and export compliance manual written to your operations
CF-28 and audit response drafted by the team that built your records
A CargoTrans compliance lead will review your procedures, screening, and records and flag the gaps that draw penalties.
Protected by reCAPTCHA. We respond within 1 business day. No spam, ever.
Control Tower
Trade Compliance Screening, Tracked Live
Our supply chain visibility service ties each shipment to its screening result, license status, and document set, so a party that fails a check stops before the goods move.
Compliance owners see which entries are missing records or approaching a response deadline, turning recordkeeping from a quarterly fire drill into a standing, monitored state. If you would rather run those controls in your own systems, CargoTrans licenses the underlying trade compliance software separately; this page is the managed program our team runs for you.
Because every classification, value, and screening decision is captured when the shipment moves, even across a multimodal transportation routing, a Focused Assessment or Request for Information is answered from the file rather than reconstructed under a deadline.
The program extends to regulated flows such as our FDA initial importer program, so agency obligations are managed inside the same controls, not bolted on later.
What does trade compliance management actually involve?
Trade compliance management is the set of policies, procedures, records, and checks that keep your import and export activity inside U.S. law. On the import side it covers exercising reasonable care over classification, valuation, and country of origin, paying the correct duties, and retaining entry records for five years. On the export side it covers classifying your products under export control rules, screening every party against restricted lists, obtaining licenses when required, and filing electronic export information. Wrapped around both is a written manual, staff training, internal audits, and a defined way to answer regulators. The point is not paperwork for its own sake; it is being able to prove, on demand, that your company knew and followed its obligations on every shipment.
What does reasonable care mean and who is responsible for it?
Reasonable care is the legal standard the Customs Modernization Act places on the importer of record. It means you, not your broker, are responsible for using reasonable care to enter, classify, and value your goods correctly and to provide CBP accurate information. Hiring a broker does not transfer this duty; it helps you meet it. In practice, exercising reasonable care means having written procedures, asking for and following binding rulings when classification is unclear, keeping the documents that support each declaration, and correcting errors when you find them. CBP judges reasonable care by what you did before the entry, not by the outcome. A company that documents its process and acts on what it learns is far better positioned in an audit than one that simply trusted whatever its supplier wrote on the invoice.
What is denied party screening and how often should we screen?
Denied party screening checks the companies and people you do business with against government restricted lists, including the OFAC Specially Designated Nationals list, the BIS Entity List, the Denied Persons List, and debarred party lists. Doing business with a listed party, even unknowingly, can trigger serious civil and criminal penalties. You should screen every customer, supplier, freight forwarder, bank, and consignee, and you should screen them on every transaction rather than only at onboarding, because the lists change constantly and so do the parties in a shipment. Automated screening at the point a purchase order or shipment is created, plus periodic rescreening of your master data, is the practical standard. We build screening into the workflow so a hit stops the shipment before it moves rather than surfacing after the fact.
Do export controls apply to my company if I only import?
Often, yes. Export controls reach more companies than people expect. If you re-export goods, ship samples or repair returns abroad, send technology or software to a foreign national even inside the United States, or resell imported items to overseas buyers, the Export Administration Regulations can apply. Products with a specific Export Control Classification Number, or anything on the U.S. Munitions List under ITAR, may need a license before leaving the country. Even items that fall under the general EAR99 category still require you to screen the destination, end user, and end use. The safe approach is to classify your products, understand which of your flows count as exports, and screen every outbound party, so a routine shipment abroad does not become a controlled export you failed to license.
How long do I have to keep import and export records?
The general rule for U.S. import records is five years from the date of entry, covering entry summaries, invoices, packing lists, payment records, and any documents that support the classification, value, and origin you declared. Export records are generally kept five years from the date of export or from the license expiration. Certain drawback and program records run longer. The obligation is not just to keep the documents but to produce them promptly if CBP asks, which is where disorganized archives cause problems. We index your records by entry and export so any file can be pulled in minutes rather than reconstructed, which matters when a Request for Information gives you a fixed number of days to respond with supporting evidence.
What is a CF-28 and how should we respond?
A CF-28 is a Request for Information CBP sends when it wants more detail about an entry, often about classification, value, or country of origin. It is not yet a penalty, but how you answer shapes what happens next. You typically have thirty days to respond, and a weak or late response frequently leads to a CF-29 Notice of Action that changes your classification or rate, or worse. The right response is complete, accurate, and backed by the documents already in your file: invoices, purchase orders, product specifications, and any rulings that support your position. Because our compliance program captures that evidence when the shipment moves, a CF-28 is answered from the record instead of a last-minute scramble, and we involve trade counsel when the amount or exposure warrants it.
Do we need a written compliance manual, and what goes in it?
A written manual is not legally mandatory for every importer, but it is the single strongest piece of evidence that your company exercises reasonable care, and regulators expect serious traders to have one. It also keeps your program from living only in one experienced employee's head. A good manual assigns clear responsibility for compliance decisions, documents your procedures for classification, valuation, and origin, defines your screening and licensing steps, sets recordkeeping rules, and describes how you handle errors, disclosures, and regulator requests. It should reflect your actual products, trade lanes, and systems rather than a generic template. We write the manual to your operations, train your staff against it, and review it on a schedule so it stays current as your sourcing and the rules change.
What happens during a CBP Focused Assessment or audit?
A Focused Assessment is CBP's structured audit of an importer's internal controls. It usually starts with a questionnaire about how your company manages compliance, followed by a review of sample entries to test whether your declared classifications, values, and origins are supported and whether your controls actually work. If CBP concludes your controls are adequate, the assessment closes. If it finds gaps, it can expand into a detailed review, propose rate adjustments, and assess duties and penalties on past entries. The companies that come through cleanly are the ones that can hand over an organized record set and point to written procedures they demonstrably follow. We prepare clients for assessments by running the same tests internally first, so weaknesses are found and fixed on our timeline rather than CBP's.
How is this different from what our customs broker already does?
A broker files your entries and helps you clear cargo, which is essential but transactional. Trade compliance management is the program around those entries: the written procedures, screening, export controls, recordkeeping, training, and audit readiness that prove your company as a whole meets its legal duties. A broker acts on the information you give it; a compliance program governs whether that information is right and whether you can defend it later. The two work best together. At CargoTrans the compliance team and the brokerage desk are the same organization, so the controls we design are the controls your entries are actually filed against, and there is no gap between what your manual says and what gets declared to CBP.
What does it cost to build and run a trade compliance program?
Pricing usually splits into a one-time build and an ongoing run. The build covers the gap assessment, risk profiling, and writing your procedures and manual, and it is scoped to the number of commodities, trade lanes, and entities you operate, since a single-product importer is far less work than a multi-entity exporter. The ongoing run covers denied party screening, periodic internal audits, recordkeeping oversight, and drafting responses when a regulator writes to you. Screening is often priced by the volume of parties or transactions checked. Training is usually a fixed fee per session. We scope the program to your actual risk rather than selling a fixed package, because a company shipping controlled technology needs more than one importing a single benign commodity. You get a defined build price and a predictable monthly run cost.
How long does it take to stand up a compliance program from scratch?
A working program is usually in place within four to eight weeks, though the timeline scales with your complexity. The first week or two is the gap assessment and risk profiling, where we review your current procedures, records, and screening against what the law requires and rank your exposure by commodity and trade lane. Writing the procedures and the manual takes another two to three weeks. Turning on screening and recordkeeping workflows and training your staff runs in parallel toward the end. A single-commodity importer can be live faster; a multi-entity operation with export-controlled products takes longer because there are more classifications and flows to document. We prioritize the highest-risk gaps first, so the exposures most likely to draw a penalty are closed early rather than waiting for the full program to finish.
What happens if a denied party screening returns a potential match?
A screening hit is not automatically a blocked deal, but it does stop the transaction until it is resolved. Most hits are potential matches on name or address rather than confirmed ones, so the first step is to review the match quality and gather identifying details to confirm whether your counterparty is actually the listed party. If it is a false positive, we document the review and release the shipment, keeping the record in case a regulator asks later. If it is a true match, the transaction must not proceed, and depending on the list and the facts you may have a reporting obligation to the relevant agency. The critical point is that the decision and its evidence are recorded, because acting on a hit without documenting the review is itself a compliance weakness. We build that review-and-document step into the workflow.
How does a compliance program handle FDA or other agency-regulated goods?
Partner government agency rules sit inside the same program rather than beside it. If you import products regulated by the FDA, USDA, EPA, or another agency, your procedures have to cover the extra registrations, codes, and reporting those agencies require, and your screening and recordkeeping have to capture that data too. For medical devices, for example, our FDA initial importer program manages establishment registration, listing, and prior notice as a defined part of the broader controls. The advantage of governing agency obligations inside one program is that a device or food shipment is not treated as an exception handled by a different team; it runs through the same reasonable care, screening, and records everything else does. That is what keeps a regulated shipment from being the one that slips through an otherwise disciplined process.
What documents and data does a compliance program actually maintain?
The program maintains the full evidentiary record behind every entry and export. On the import side that is the entry summary, commercial invoice, packing list, bill of lading, proof of duty payment, and any ruling or certificate that supports your declared classification, value, and origin. On the export side it is the electronic export information filing, the commodity classification, license determinations, and destination and end-user screening results. Around those sit your written procedures, your compliance manual, training records, internal audit findings, and the log of how each denied party hit was resolved. All of it must be retained for five years and produced on demand. We index the record by entry and export so a Request for Information or a Focused Assessment is answered from an organized file, pulled in minutes, rather than reconstructed under a deadline.