WCO Authorised Economic Operator (AEO) Framework
The World Customs Organization (WCO) SAFE Framework of Standards establishes the Authorised Economic Operator (AEO) programme, providing mutual recognition of trusted traders in international supply chains. AEO-certified operators demonstrate compliance with supply chain security standards and customs requirements in exchange for facilitated customs processing. Implemented by 100+ countries with mutual recognition agreements enabling global trade facilitation.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Benefits Management
| Code | Title |
|---|---|
| AEO-18 | Trade Facilitation Benefits Realisation |
Business Continuity
| Code | Title |
|---|---|
| AEO-12 | Crisis Management and Incident Recovery |
Cargo Security
| Code | Title |
|---|---|
| AEO-6 | Cargo Security and Conveyance Integrity |
Change Management
| Code | Title |
|---|---|
| AEO-17 | Notification of Changes |
Compliance History
| Code | Title |
|---|---|
| AEO-2 | Customs Compliance Record |
Customs Compliance
| Code | Title |
|---|---|
| AEO-CC-1 | Compliance History |
| AEO-CC-2 | Commercial Record Management |
| AEO-CC-3 | Financial Viability |
| AEO-CC-4 | Code of Conduct |
Customs Procedures
| Code | Title |
|---|---|
| AEO-14 | Customs Procedures and Declaration Accuracy |
Financial Standing
| Code | Title |
|---|---|
| AEO-4 | Financial Solvency |
Governance
| Code | Title |
|---|---|
| AEO-20 | AEO Governance and Accountability |
Human Resources Security
| Code | Title |
|---|---|
| AEO-8 | Personnel Security |
Information Security
| Code | Title |
|---|---|
| AEO-9 | Information Security and IT Systems |
Information and Technology
| Code | Title |
|---|---|
| AEO-IT-1 | Information Security |
| AEO-IT-2 | Advance Electronic Information |
| AEO-IT-3 | Document and Data Integrity |
Mutual Recognition
| Code | Title |
|---|---|
| AEO-15 | Mutual Recognition Arrangements |
Personnel Security
Requirements for ensuring personnel suitability and managing insider threats
| Code | Title |
|---|---|
| AEO-PS-1 | Employee Vetting |
| AEO-PS-2 | Security Awareness Training |
| AEO-PS-3 | Access Management |
| CTPAT-PE-1 | Pre-Employment Verification |
| CTPAT-PE-2 | Employee Screening |
| CTPAT-PE-3 | Education and Training |
| DSPF-PERS-1 | Personnel Suitability |
| DSPF-PERS-2 | Security Clearances |
| DSPF-PERS-3 | Ongoing Personnel Assessment |
| DSPF-PERS-4 | Insider Threat Management |
| DSPF-PERS-5 | Security Awareness and Training |
| ISM-0252 | Cyber Security Awareness Training |
| ISM-0414 | Database hardening |
| ISM-0434 | Need to know enforced |
| ISM-1146 | Targeted Cyber Security Training |
| ISM-1175 | Privileged workstations |
| ISM-1503 | Separate Privileged Operating Environments |
| ISM-1507 | Privileged Access Limitation |
| ISM-1508 | Privileged Access Review |
| PSPF-PERS-1 | Eligibility and Suitability |
| PSPF-PERS-2 | Security Clearances |
| PSPF-PERS-3 | Ongoing Suitability |
| PSPF-PERS-4 | Separation and Transfer |
Physical Security
| Code | Title |
|---|---|
| AEO-5 | Security and Safety Standards: Premises |
Programme Governance
| Code | Title |
|---|---|
| AEO-1 | AEO Programme Eligibility and Legal Basis |
Record Keeping
| Code | Title |
|---|---|
| AEO-3 | Commercial and Transport Records System |
Risk Management
| Code | Title |
|---|---|
| AEO-11 | Risk Management and Threat Assessment |
Self Assessment
| Code | Title |
|---|---|
| AEO-13 | Self Assessment and Internal Audit |
Status Management
| Code | Title |
|---|---|
| AEO-19 | Suspension, Withdrawal and Revocation Procedures |
Supply Chain Security
| Code | Title |
|---|---|
| AEO-7 | Business Partner Security |
| AEO-SC-1 | Cargo Security |
| AEO-SC-2 | Conveyance Security |
| AEO-SC-3 | Premises Security |
| AEO-SC-4 | Trading Partner Security |
| CTPAT-SCS-01 | Physical Security |
| CTPAT-SCS-02 | Personnel Security |
| CTPAT-SCS-03 | Conveyance and Cargo Security |
| EU-CHIPS-SUP-01 | Supply Chain Monitoring |
| EU-CHIPS-SUP-02 | Crisis Assessment and Response |
| EU-CHIPS-SUP-03 | International Partnerships |
| EU-CRMA-SUP-01 | Strategic Benchmarks |
| EU-CRMA-SUP-02 | Strategic Projects Recognition |
| EU-CRMA-SUP-03 | Supply Chain Monitoring |
| NIS2-IA-7 | Supply Chain Security Policy |
| NIS2-IA-8 | Supplier Security Assessment |
| NRF-4 | Supply Chain Risk Identification |
| NRF-5 | Third-Party Partner Standards |
| NRF-6 | Vendor Risk Management |
| UKTSA-SC-01 | Supply Chain Risk Assessment |
| UKTSA-SC-02 | High-Risk Vendor Restrictions |
| UKTSA-SC-03 | Vendor Diversification |
| UKTSA-SC-04 | Third-Party Access Controls |
| WCO-SAFE-SCS-01 | Advance Electronic Information |
| WCO-SAFE-SCS-02 | Risk Management |
| WCO-SAFE-SCS-03 | Non-Intrusive Inspection |
Supply Chain Security
Customs security and risk management
| Code | Title |
|---|---|
| AEO-7 | Business Partner Security |
| AEO-SC-1 | Cargo Security |
| AEO-SC-2 | Conveyance Security |
| AEO-SC-3 | Premises Security |
| AEO-SC-4 | Trading Partner Security |
| CTPAT-SCS-01 | Physical Security |
| CTPAT-SCS-02 | Personnel Security |
| CTPAT-SCS-03 | Conveyance and Cargo Security |
| EU-CHIPS-SUP-01 | Supply Chain Monitoring |
| EU-CHIPS-SUP-02 | Crisis Assessment and Response |
| EU-CHIPS-SUP-03 | International Partnerships |
| EU-CRMA-SUP-01 | Strategic Benchmarks |
| EU-CRMA-SUP-02 | Strategic Projects Recognition |
| EU-CRMA-SUP-03 | Supply Chain Monitoring |
| NIS2-IA-7 | Supply Chain Security Policy |
| NIS2-IA-8 | Supplier Security Assessment |
| NRF-4 | Supply Chain Risk Identification |
| NRF-5 | Third-Party Partner Standards |
| NRF-6 | Vendor Risk Management |
| UKTSA-SC-01 | Supply Chain Risk Assessment |
| UKTSA-SC-02 | High-Risk Vendor Restrictions |
| UKTSA-SC-03 | Vendor Diversification |
| UKTSA-SC-04 | Third-Party Access Controls |
| WCO-SAFE-SCS-01 | Advance Electronic Information |
| WCO-SAFE-SCS-02 | Risk Management |
| WCO-SAFE-SCS-03 | Non-Intrusive Inspection |
Training
| Code | Title |
|---|---|
| AEO-10 | Security Training and Awareness |
Validation
| Code | Title |
|---|---|
| AEO-16 | AEO Validation and Re-Validation |
Validation and Authorization
| Code | Title |
|---|---|
| AEO-VA-1 | Validation Process |
| AEO-VA-2 | Authorization and Accreditation |
| AEO-VA-3 | Mutual Recognition |
| AEO-VA-4 | Continuous Monitoring and Re-Validation |
Your Compliance Coverage
If you comply with WCO Authorised Economic Operator (AEO) Framework, you already cover:
NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements
33%
26 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
32%
25 controls mapped
Compare →C-TPAT — Customs-Trade Partnership Against Terrorism
32%
25 controls mapped
Compare →+ 590 more: Defence Security Principles Framework (DSPF) (30%), Protective Security Policy Framework (PSPF) Release 2024 (30%)
See all 593 mapped frameworks ↓Maps to 593 other frameworks
Frequently Asked Questions
What is WCO Authorised Economic Operator (AEO) Framework?
WCO Authorised Economic Operator (AEO) Framework is a compliance framework from International (WCO) with 25 domains and 79 controls. The World Customs Organization (WCO) SAFE Framework of Standards establishes the Authorised Economic Operator (AEO) programme, providing mutual recognition of trusted traders in international supply chains. AEO-certified operators demonstrate compliance with supply chain security standards and customs requirements in exchange for facilitated customs processing. Implemented by 100+ countries with mutual recognition agreements enabling global trade facilitation. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does WCO Authorised Economic Operator (AEO) Framework have?
WCO Authorised Economic Operator (AEO) Framework has 79 controls organised across 25 domains. The largest domains are Supply Chain Security (25 controls), Personnel Security (23 controls), Customs Compliance (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does WCO Authorised Economic Operator (AEO) Framework map to?
WCO Authorised Economic Operator (AEO) Framework maps to 593 other compliance frameworks. The top mapping partners are NIST SP 800-171A Rev 3 — Assessing CUI Security Requirements (33% coverage), TISAX — Trusted Information Security Assessment Exchange (32% coverage), C-TPAT — Customs-Trade Partnership Against Terrorism (32% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with WCO Authorised Economic Operator (AEO) Framework compliance?
Start your WCO Authorised Economic Operator (AEO) Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about WCO Authorised Economic Operator (AEO) Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 79 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required