ISO 28000 Supply Chain Security Implementation Training Course
| Course code | SD-SCM-033 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Supply Chain Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Supply chain disruption, cargo theft, counterfeit substitution, unauthorised access, cyber-enabled manipulation of logistics data and supplier security failures can interrupt customer service and expose organisations to contractual, financial and reputational loss. ISO 28000 provides a management-system framework for controlling these risks across procurement, transport, warehousing, customs interfaces and third-party logistics operations. This course helps professionals translate the standard from a compliance requirement into operating controls, evidence and accountable ownership across the supply chain.
Participants work through the ISO 28000:2022 requirements clause by clause and learn how to establish scope, context, security objectives, risk criteria, controls, documented information, performance measures and corrective-action processes. They use risk registers, process maps, supplier-security assessment criteria, incident reporting workflows and internal audit checklists to connect security risks to practical operational decisions. Particular attention is given to managing outsourced providers, high-risk lanes, site access, cargo integrity, information exchange and business continuity arrangements.
The five-day programme combines instructor-led interpretation of the standard with facilitated workshops based on a multi-node supply chain scenario. Participants develop a structured ISO 28000 implementation pack for their own organisation or a realistic case organisation: a scope statement, stakeholder and context analysis, risk assessment, control treatment plan, KPI set, document-control approach and implementation roadmap. They leave with templates that can be adapted for a gap assessment, management review and internal audit programme.
This intermediate course is suited to supply chain, procurement, logistics, security, quality and risk professionals who have responsibility for designing, operating, reviewing or assuring supply chain security controls.
Course objectives
By the end of this course, participants will be able to:
- Interpret ISO 28000:2022 clauses and translate them into supply chain security management-system requirements
- Define an ISO 28000 scope statement covering organisational boundaries, supply chain interfaces and outsourced activities
- Conduct a supply chain security risk assessment using threat, vulnerability, consequence and likelihood criteria
- Build a risk register and risk treatment plan linking priority risks to named operational controls and owners
- Design supplier and logistics-provider security assessment criteria for procurement qualification and contract monitoring
- Create measurable security objectives, KPIs and reporting dashboards for management review
- Prepare documented information, internal audit checklists and corrective-action records aligned to ISO 28000
- Produce a phased ISO 28000 implementation roadmap with milestones, resources, responsibilities and evidence requirements
Benefits of attending
For you
- Gain the ability to lead or contribute credibly to an ISO 28000 implementation project
- Build evidence-based supplier security requirements that strengthen procurement and logistics decisions
- Develop a reusable risk-assessment and treatment approach for cargo, facilities, data and third-party exposures
- Improve readiness to support ISO 28000 internal audits, management reviews and certification preparation
- Leave with an implementation pack that demonstrates practical management-system capability to employers
For your organisation
- Creates a consistent method for identifying and treating security risks across supply chain nodes and partners
- Improves supplier and carrier oversight through defined security criteria, contractual controls and review evidence
- Reduces the likelihood and impact of theft, tampering, unauthorised access and security-related service disruption
- Provides management with measurable security objectives, KPIs, incident trends and corrective-action status
- Accelerates ISO 28000 readiness through a documented roadmap, templates and trained internal implementation resource
Target competencies
Who should attend
- Supply Chain Managers — who must maintain continuity and security across suppliers, warehouses, carriers and distribution networks
- Procurement Managers — who need to embed supplier security requirements into qualification, tendering and contract management
- Logistics and Distribution Managers — who oversee cargo movement, carrier performance, route exposure and delivery integrity
- Corporate Security Managers — who need a management-system approach for extending security controls beyond company sites
- Quality, Compliance and Internal Audit Professionals — who assess control effectiveness and prepare organisations for ISO-based audits
- Risk and Business Continuity Managers — who coordinate risk treatment, incident response and resilience planning across supply chain functions
Requirements and prerequisites
Participants should have working familiarity with their organisation’s procurement, logistics, warehousing, transport or supplier-management processes. Experience using basic risk concepts such as likelihood, impact, controls and risk ownership is helpful, as is the ability to read process maps, procedures and supplier records. Participants should ideally bring examples of their current supply chain scope, key third parties or known security concerns. Prior ISO 28000 implementation or audit experience is not required, and no specialist security qualification, coding ability or certification-body audit training is assumed. Basic spreadsheet use is sufficient for the workshop templates.
Training methodology
Instructor-led sessions explain each ISO 28000:2022 requirement in the context of procurement, logistics and security operations. Participants then apply the clauses to a multi-party supply chain case involving a manufacturer, freight forwarder, warehouse operator and overseas supplier. Workshops use process mapping, risk-register scoring, control selection, supplier-assessment design and audit-evidence review. Small groups challenge control decisions and present recommendations to a simulated management review. The final session converts the case work into an organisation-specific 90-day implementation plan.
Course outline
Day 1: ISO 28000 framework, context and scope
- Purpose and structure of ISO 28000:2022
- Annex SL management-system architecture
- Supply chain security threats and exposure points
- Organisational context and interested-party analysis
- Defining management-system boundaries and applicability
- Leadership responsibilities and security policy requirements
- Process mapping across suppliers, transport and warehousing
Workshop: Participants map a case supply chain, identify critical interfaces and draft an ISO 28000 scope statement with exclusions and justification.
Day 2: Security risk assessment and treatment
- Risk criteria and risk appetite definition
- Threat, vulnerability and consequence analysis
- Likelihood and impact scoring models
- Risk-register design and control-owner assignment
- Cargo theft, tampering and counterfeit risk scenarios
- Third-party, route and site security exposures
- Risk treatment options and residual-risk acceptance
Workshop: Participants complete a scored security risk register and prioritised treatment plan for high-risk supply chain scenarios.
Day 3: Operational controls and supplier assurance
- Security objectives and operational planning
- Physical security and access-control measures
- Cargo integrity, seals and chain-of-custody controls
- Supplier due diligence and security prequalification
- Security clauses in logistics and supplier contracts
- Information security at supply chain handovers
- Incident response and business continuity integration
Workshop: Participants design a supplier-security questionnaire and control matrix for a contracted warehouse and transport provider.
Day 4: Documented information, measurement and audit
- ISO 28000 documented-information requirements
- Procedure, record and document-control design
- Security KPI and performance-evaluation methods
- Incident, nonconformity and corrective-action records
- Management review inputs and decision outputs
- ISO 19011 internal audit principles
- Audit trails, evidence sampling and finding statements
Workshop: Participants conduct a tabletop internal audit, record objective evidence and write nonconformity and corrective-action reports.
Day 5: Implementation planning and continual improvement
- ISO 28000 gap-assessment methodology
- Implementation work-breakdown structure
- Roles, competence and security-awareness planning
- Resource, budget and technology considerations
- Certification-readiness evidence and audit preparation
- Continual improvement and corrective-action governance
- Ninety-day implementation roadmap development
Workshop: Participants assemble and present an ISO 28000 implementation pack containing their gap priorities, roadmap, owners, milestones and evidence plan.
Tools & standards covered
ISO 28000:2022, ISO 31000:2018, ISO 19011:2018, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Supply Chain Management
Microsoft Dynamics 365 Supply Chain Management Training Course
Procurement and supply chain teams need more than transaction-level familiarity with Dynamics 365 Supply Chain Management. They must configu…
Supply Chain Control Tower Skills for Logistics Managers Training Course
Logistics managers are increasingly expected to respond to late shipments, capacity constraints, inventory exceptions and supplier disruptio…
SAP Integrated Business Planning Supply Chain Training Course
Supply chain teams often plan demand, inventory, supply and capacity in separate spreadsheets or disconnected systems, then spend critical p…
Public Sector Supply Chain Governance Training Course
Public-sector supply chains operate under requirements that private-sector teams do not face to the same extent: transparent competition, de…