Frameworks / Authorised Economic Operator (AEO) Programmes - Global Standards / AEO-4 Authorised Economic Operator (AEO) Programmes - Global Standards
AEO Conditions and Requirements (SAFE Annex IV)
Authorised Economic Operator (AEO) Programmes - Global Standards AEO-4: Financial Viability The operator is in good financial standing sufficient to fulfil its commitments given the characteristics of its business model and activity, assessed using absolute and relative financial indicators within the national programme's vetting and validation procedures.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 123 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures IEC62443-21 Supply chain risk management for critical components IEC62443-22 Configuration management for OT systems IEC62443-23 Change management procedures IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper ISO-20400-7.3 Supplier selection ISO-20400-7.4 Contract management and review ISO-20400-7.5 Reviewing and learning ISO27019-22 Configuration management for OT systems ISO27019-23 Change management procedures ISO27019-24 Vulnerability assessment for critical systems AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition RMI-DD-3 Red Flag Review RMI-MS-2 Cobalt Standard RMI-RMAP-2 Risk-Based Audit Approach SII-P2-09 Outsourcing Requirements SII-P2-12 Written Policies SII-P3-06 SFCR Section B: System of Governance CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing CPG-6.A Vendor and Supplier Incident Reporting CPG-6.B Supply Chain Incident Reporting A.1 Point-of-Care Testing Additional Requirements ISO-15189-6.8 Externally provided products and services ISO28001-PC-03 Supply Chain Incident Reporting ISO28001-PC-04 Supply Chain Continuity Planning ISO27003-4.2 Understanding the needs and expectations of interested parties ISO27003-8.1 Operational planning and control DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing SASB-1 Business Model + Innovation (BMI) SASB-BMI-3 Supply Chain Management CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records AS9100D-8.4 Control of Externally Provided Processes, Products, Services Clause 3 Suppliers and service providers ACQ.4 Supplier Monitoring Mat 03 Responsible Sourcing of Materials BMA-8 Third-Party, Outsourcing and Cloud Risk CJIS-19 Supply Chain Risk Management FedRAMP-SupplyChain-SBOM FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF) Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) GAMP5-2nd-Edition-AI-Cloud-Agile-CSA 2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA) GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe ISO22316-14 Supply chain continuity ISO-26000-6.6 Fair operating practices ISO-41001-8.4 Control of outsourced processes and services ISO-50001-8.3 Procurement ISO23894-A.6 AI System Security 27010-15.1 Incident Management 27011-5.6 Supplier relationships and telecom supply chain ISO22317-14 Supply chain continuity ISO22318-14 Supply chain continuity NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification OECDMNE-5 Environment, Climate, and Biodiversity OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08) AODACAN-2 Accessible Procurement of Goods, Services, Facilities PASONE-3 Personnel Security, Vetting, Awareness, and Training PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain IM8-TPM.4 Supply Chain Risk Management ISMSP-PI-03 Third-Party Provision and Outsourcing GT-3 Supply Chain Compromise UKOPRES-5 Third-Party Risk, Concentration Risk UKGAMBLE-4 Resilience and Incident Response SEMD-PS-3 Supply Chain Security UK-TSA-NET-03 Supply Chain Security USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability EU-UCC-02 Authorised Economic Operator (AEO) Authorisation VERMONTAICDA-4 Vermont AG Enforcement and Cure Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AEO Conditions and Requirements (SAFE Annex IV) Query this from an agent The graph holds this control, the 123 it maps to, and the evidence behind each claim, over MCP and REST.