The Portcullis Standard
A clear standard for reducing criminal-ingress risk.
The Portcullis Standard sets out what good looks like for a freight business protecting itself from criminal infiltration. It is organised into nine domains, each with an objective and a set of controls assessed during certification.
The Standard defines the minimum controls a Portcullis Certified organisation must demonstrate and maintain.
Governance & Accountability
Senior leadership owns criminal-ingress risk, with named responsibilities and regular review.
What this domain covers
- Named senior owner
- Documented security policy
- Risk assessment
- Management review
Detailed control requirements are published in the full Standard.
People & Recruitment
People are recruited and onboarded with checks proportionate to the access they will hold.
What this domain covers
- Pre-employment screening
- Reference and identity checks
- Temporary and agency staff
- Leavers and access removal
Detailed control requirements are published in the full Standard.
Insider Threat & Vulnerability
The business recognises that staff can be targeted, and supports people before they are compromised.
What this domain covers
- Security-sensitive roles
- Segregation of duties
- Changes in behaviour
- Wellbeing and support
Detailed control requirements are published in the full Standard.
Counterparty Due Diligence
Customers, agents and suppliers are checked before work begins and when circumstances change.
What this domain covers
- CLUES checks
- Overseas agents
- New and changed accounts
- Records of checks
Detailed control requirements are published in the full Standard.
Communications & Identity Verification
Instructions are acted on only when the sender and channel have been verified.
What this domain covers
- Cloned and look-alike domains
- Changed instructions
- Call-back verification
- Release of goods
Detailed control requirements are published in the full Standard.
Bribery, Coercion & Criminal Approach
Staff know how criminal approaches happen and are protected when they report them.
What this domain covers
- Offers and gifts
- Threats and duress
- Approach reporting
- Protection for staff
Detailed control requirements are published in the full Standard.
Incident Reporting & Escalation
Concerns are raised early, escalated quickly and reported to the right authorities.
What this domain covers
- Confidential reporting
- Escalation routes
- Evidence preservation
- External reporting
Detailed control requirements are published in the full Standard.
Training & Security Culture
Everyone understands the risks relevant to their role and feels able to challenge.
What this domain covers
- Induction training
- Role-based refreshers
- Awareness campaigns
- Leadership example
Detailed control requirements are published in the full Standard.
Intelligence & Continuous Improvement
The business learns from incidents and emerging threats and improves its controls.
What this domain covers
- Threat awareness
- Lessons learned
- Control testing
- Corrective action
Detailed control requirements are published in the full Standard.
See how your controls compare.
The Initial Exposure Check covers the same ground in fifteen questions.