Authorised Economic Operator (AEO) Programmes - Global Standards
WCO SAFE Pillar 2 - Customs-to-Business

Authorised Economic Operator (AEO) Programmes - Global Standards P2-S3: Authorization

The Customs administration, with the trade community, designs validation processes or quality accreditation procedures that grant Authorized Economic Operator status and define the tangible benefits that follow.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 3 controls

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

SOC 2 · 2 controls

  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-SOC1-06 Transaction Processing Controls
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics
  • 62351-8 Role-based access control (RBAC)

ISO 27799:2025 · 1 control

  • ISO27799-01 ePHI access controls and authorization

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27043:2015 · 1 control

  • ISO27043-14 Privileged access management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design

ISO/SAE 21434 · 1 control

  • ISO21434-14 Privileged access management
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-190 · 1 control

  • NIST190-08 Privileged access in cloud environments

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

PTES · 1 control

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • SHAREASSESS-2 Access Control, Identity, Authentication

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • SIGSTORE-2 Transparency Log (Rekor) and Verification

South Korea ISMS-P · 1 control

  • ISMSP-AC-01 Access Control Policy
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UK-TSA-NET-02 Access Control and Authentication
  • ACE-CR-4 Cargo Release Authorization
  • UGA-10 Sensitive Personal Data Prohibition

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in WCO SAFE Pillar 2 - Customs-to-Business

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.