Today’s international supply chains are constantly changing, and flexibility is often what keeps cargo moving. Capacity shortages, regional limitations, and cost pressures frequently push companies to rely on subcontractors. For members of the Customs Trade Partnership Against Terrorism (CTPAT), though, subcontracting isn’t just about finding capacity or lowering costs, it directly affects cargo security. Who is selected, how they are approved, and how closely they are monitored determine whether custody and accountability are maintained or inadvertently lost. When subcontracting becomes unclear or slips into undisclosed double brokering, the risks rise quickly, often leading to security breaches, cargo theft, compliance issues, and reputational damage.
Expectations on Subcontracting within CTPAT
From the start, CTPAT was built on the understanding that supply chains are complex and interconnected, but also that every additional handoff introduces risk if it isn’t carefully managed. That responsibility is defined through the idea of “business partners,” which includes carriers, brokers, 3PLs, warehouses, and anyone else who touches the cargo or its data. The expectation is straightforward: even when work is outsourced, security responsibility stays with the CTPAT member. Companies may delegate the work, but they still own the risk and must be able to show who had control of their cargo at every step.
This expectation brings due diligence to the forefront. Effective CTPAT programs do not treat partner vetting as a one-time exercise or a check‑the‑box requirement. They apply a structured, risk‑based approach that evaluates who is involved, what access they have, and how their controls align with CTPAT’s Minimum Security Criteria (MSC). For transportation, in particular, CBP has emphasized the importance of knowing who is physically moving the cargo – not just who accepted the load or issued the paperwork. That distinction has become increasingly important in an era of digital fraud and identity manipulation.
Risks of Double Brokering
Where subcontracting becomes especially problematic is in cases of double brokering. Load brokering is a common practice – typically in the ground transportation environment – wherein a load broker (also known as a freight broker) connects shippers with transportation providers.
Double brokering occurs when a service provider accepts a shipment and then re‑brokers it – often multiple times – without the knowledge or consent of the shipper or original contracting party. Each undisclosed layer diminishes transparency and weakens the chain of custody. For CTPAT, double brokering is not simply a contractual concern; it is a security vulnerability. Program guidance makes clear that uncontrolled re‑brokering undermines the integrity of the supply chain by introducing unvetted actors and eroding accountability.
The risks associated with double brokering are not theoretical. A widely reported cargo theft in late 2024 illustrated just how sophisticated and damaging these schemes can be. Two truckloads of premium Mexican tequila vanished while in transit from Laredo, Texas after being unknowingly re‑brokered to a fraudulent carrier. The perpetrators relied not on force, but on forged business credentials, videos staged to make it look like the truck had broken down, fabricated communications, and spoofed GPS data to maintain the illusion of legitimacy. By the time the deception was uncovered, roughly one million dollars worth of product had disappeared. Importantly, the initial carriers appear to have been legitimate, highlighting how easily criminal activity can hide within otherwise lawful operations when controls break down.
For CTPAT members and supply chain leaders, incidents like this underscore a critical reality: criminal networks exploit gaps in oversight. They thrive in environments where subcontracting decisions are rushed, not thoroughly vetted, exceptions made based upon cost or lack of capacity, and responsibility becomes diffused across too many parties.

As the amount of subcontracting increases, more complexity and risk is introduced into supply chains
How to Minimize Risks
Organizations that perform well under CTPAT validation tend to share common characteristics. They favor certified and well vetted partners, embed clear subcontracting and notification requirements into contractual agreements, and maintain real‑time visibility regarding who has custody of cargo at every stage. They treat unexpected carrier changes, unexplained delays, and inconsistencies in tracking data as security events – not routine inconveniences. Just as importantly, they invest in training so that operational teams understand how seemingly minor deviations can signal much larger risks. Those involved in the selection, procurement, and managing the relationship with indirect service providers need to be fully aligned with the CTPAT committee team.
CTPAT does not require perfection, but it does require discipline. Subcontracting can coexist with strong security when it is deliberate and transparent. Double brokering, when left unchecked, cannot. For companies operating in high-value or high‑risk supply chains, the central question is not whether subcontracting exists, but whether it is governed well enough to withstand scrutiny. If Customs asked today, could your organization clearly demonstrate who controlled your cargo at every step – and why? The answer to that question increasingly defines continued program participation.
Bradd Skinner, one of our CTPAT Navigator Senior Advisors, summed it up like this: “A common mistake CTPAT members make is using a load broker and assuming their carriers meet the MSC, always verify who is handling your cargo.” Feel free to reach out to CT Strategies if you would like to discuss specific questions in this regard or any other matter.




