Skip to main content

Initial Exposure Check

Portcullis Initial Exposure Check

Fifteen questions about your current controls, across five areas, showing where they may need strengthening.

  • Around 5 minutes
  • 15 questions
  • Immediate indicative profile

This is an initial exposure check, not a formal audit or certification assessment.

Answer every question. If you are not sure, choose Not sure.

Governance

01Is a named senior person responsible for protecting the business from criminal infiltration?
02Does management review criminal-infiltration risk at least once a year?
03When an incident or near miss happens, do you review and improve your controls?

People

04Do you carry out identity, right-to-work and reference checks before people start, including temporary and agency staff?
05Have you identified which roles are security-sensitive, such as those with access to releases, schedules or payments?
06Would you notice, and know how to support, a member of staff who was being pressured, in debt or approached by criminals?
07Do staff receive training on how criminals target freight businesses and their people?

Counterparties

08Do you verify new customers, agents and suppliers before working with them?
09Are those checks carried out consistently, using a documented method such as CLUES, and recorded?

Communications

10Do staff check that emails genuinely come from the organisation they claim to, including look-alike domains?
11Are changed bank, delivery or collection instructions always verified through an independent channel?
12Is access to shipment, customer and schedule information limited to those who need it?

Reporting

13Can staff raise a concern confidentially, without fear of reprisal?
14Do you have a written plan for responding to a suspected criminal incident?
15Do staff know who to escalate to internally, and when to report to external authorities?

The Initial Exposure Check is a short self-assessment, not a formal security audit. Results are indicative and based only on your answers.