Show me the DATA!

Show me the DATA! DHS seeks advance data to protect aircraft, but could it have developed a pre-departure inspection regime before the latest crisis?

By Eric Kulisch

   Department of Homeland Security officials say they will issue a new rule requiring airlines that carry cargo into the United States to submit manifest data prior to departure from a foreign airport ' but only after thoroughly testing the best methods for achieving their security goals without damaging the air cargo industry.
   Obtaining shipment information in advance of the current manifest-filing deadline ' four hours prior to arrival or at takeoff for countries less than four hours away ' is now considered a necessary step to protect aircraft, including freighters, from being blown up in flight, after plastic explosives hidden in printer cartridges were recently discovered on a UPS plane in England and at a FedEx facility in Dubai. Investigators suspect the plastic explosives, which were rigged to cell phone circuitry, were timed to detonate while the couriers' planes flew over major cities on the U.S. East Coast.
   The acknowledgement that data is virtually useless for weeding out suspicious shipments and thwarting a mid-air attack when received after planes are en route begs the question of why it took the parcel bomb plot from Yemen before officials considered revising a major gap in the nation's risk-based supply chain security regime.
   The manifest, electronically transmitted through an approved pipeline, is ostensibly filtered through CBP computers to match shipment characteristics against various risk factors and intelligence reports. Shipments that generate a red flag are subjected to non-intrusive technical or physical inspections upon arrival, but the recent al Qaeda plot targeting U.S.-bound cargo planes has DHS scrambling to revise its security protocols so that shipments can be assessed and, if necessary, held for inspection before they are loaded onto a plane.
   Soon after the bomb plot was foiled, DHS officials indicated they were working with express delivery companies and other airlines to find a way to get some of the manifest data, and possibly new data elements, before departure.
   Among the issues to be resolved are:
   ' What data is available pre-departure.
   ' How early can air carriers get complete and reliable data from customers.
   ' Which parties have the data.
   ' How to notify a freight forwarder or carrier not to load a shipment in the event of an alarm.
   ' How law enforcement officials in a foreign country can be enlisted to help resolve whether a package poses a threat.
   CBP also updated its automated cargo targeting rules to identify air cargo shipments with risk profiles similar to those of the parcel bombs that originated in Yemen.
   DHS will soon launch several demonstration programs for collecting advance air cargo data before rolling out a new rule, according to recent Senate testimony by Customs and Border Protection Commissioner Alan Bersin and John Pistole, administrator of the Transportation Security Administration.
   In conjunction with the new security directive on advance shipment data, CBP will also adjust its targeting rules to reflect TSA security concerns and establish procedures for scanning high-risk cargo overseas, Bersin said in an interview. TSA's focus is explosives and stowaways, while CBP's mission is aimed at intercepting radiological/nuclear material, narcotics, agricultural pets, outbound guns and money, and other contraband.
   'A robust, intelligence-based targeting system ' built upon pre-departure advanced air cargo data, will result in a much enhanced air cargo strategy and greater security for our nation,' the two agency heads said in their joint statement.

Security Filing. Contrary to general perception, CBP isn't seeking to push back the time at which air carriers must electronically file the cargo manifest. Instead, the agency believes that obtaining a subset of the manifest data in advance could enhance its ability to assess security risks without unduly burdening the air cargo industry, according to an agency official close to the policy deliberations.
   The manifest includes:
   ' Master and house air waybill numbers for consolidated shipments.
   ' Trip/flight number.
   ' Carrier code.
   ' Airport of origin.
   ' Airport of arrival.
   ' Scheduled date of arrival.
   ' Total piece count.
   ' Total weight.
   ' Cargo description.
   ' Shipper name and address.
   ' Consignee name and address.
   CBP is only interested in obtaining a few of the data elements on the manifest that are generally known earlier in the shipping process ' such as the cargo description and relevant addresses ' that can be run through an automated targeting system for pre-departure risk assessment, said a Customs source, who spoke not for attribution because he is not authorized to speak to the press.
   The other half of the manifest data specific to the flight the cargo is arriving on is generally not available until the plane is ready to take off and is not being sought any sooner.
   'We're not looking to take the existing manifest and back that up, but require those data elements that really have the targeting value and make sure we get those' as a separate security filing, the official said.
   The information would still come from the carriers, unlike the advance security filing now required from importers in the ocean container arena.
   Any filing deadlines could differ to accommodate different types of business models within the air cargo industry, according to the CBP source.


Shipper takeaways
' Develop a secure area in your facility to pack shipments, access controls and procedures and apply to the Transportation Security Administration's Certified Cargo Screening Program so your shipments are accepted as    pre-screened and don't have to be opened or delayed at the airport. Companies with time-sensitive, high-value or perishable products are especially considering the CCSP to ensure the integrity of their supply chains.

' Work to encourage aviation authorities, border management agencies and legislatures in other countries to adopt supply chain screening programs for air cargo so the inspection burden doesn't fall entirely on airlines and lead to lengthy backlogs and missed flights.

' Begin to think of what information could be shared earlier with freight forwarders or charter airlines as industry and government explore a system to deliver shipment information to customs authorities for pre-departure screening, giving legitimate shippers an unimpeded path to the next flight while sorting out shipments from unknown and suspicious sources for further scrutiny.
   CBP will have two pilot programs ' one for express carriers and the other for passenger airlines ' to gauge what data is available and when it accessible, as well as other operational mechanics. Several carriers have volunteered to participate in the pilot programs, and technical staffs are working out the necessary information technology connections, data elements, message formats and targeting rules to move ahead, the official said.
   Dual data streams are necessary because express carriers such as FedEx, UPS, DHL and TNT are integrated logistics companies that deal directly with regular shipping customers, have trucking networks, consolidation hubs and their own aircraft. That means they get information from tendered shipments very early, and maintain control of it throughout the process.
   Passenger airlines tend to partner with freight forwarders, who are middlemen for the shippers trying to find the most cost-effective or expedited carrier. Forwarders often subcontract with ground transportation companies or other service providers, which adds layers to the cargo handling and document preparation processes.
   The official said a separate pilot for heavyweight all-cargo carriers is not necessary because they tend to follow either the express consignment model and deal directly with shippers or deal with freight forwarders in the same way as passenger airlines.
   A second part of the pilots, which would take longer to set up than the IT component, will focus on response protocols ' such as replying with 'do not load' messages and setting up inspections for shipments that score above pre-determined risk thresholds.
   Bersin and Pistole testified that one of the challenges to simply pushing back the manifest deadline is that small carriers in some parts of the world are not fully electronic.
   According to industry experts, many shipments come from countries with limited Internet access or from forwarders that don't have electronic capability. The shipments, for example, can be moved on the first leg by a local courier and transferred to a larger airline at a major gateway. The small express company or forwarder may fill out a paper manifest or house airway bill, which requires the second airline, or a third-party filing service, to manually input the information for transmission.
   The house bill is the forwarder's own internal bill of lading, or contract with each individual customer. A forwarder can combine multiple house bills on a master bill, which represents its contract with the airline.
   Most large forwarders have the necessary software and approval to send house airway bills themselves through CBP's Automated Manifest System, after which they notify the airline. Forwarders also have the option of electronically sending their house and master bills to the airline and letting the airline submit the documentation through AMS. About 20 percent of the time, the paperwork arrives with the cargo.
   About 5 million house and master airway bills are submitted to Customs through the Automated Manifest System every month, according to Michael White, assistant director for cargo standards at the International Air Transport Association's U.S. subsidiary.
   'It's in the best interest of the forwarding community to submit their advance house airway bill data electronically, whether it's to U.S. Customs or any other agency around the world that has the capability to receive it,' White said.
   The problem for the forwarder is that it, or the airline, may not have created a master airway bill number that soon. Forwarders must put the master bill number on their house manifest as a cross reference because CBP's computers use the number to match up the master bill with the sub bills so the agency knows which plane the shipment flew on. In many cases a forwarder may still be consolidating shipments and not know which airline, or airlines, to whom it ultimately will tender a load.
   Another complication is that house bills in other languages must be translated into English before they can be sent along with the carrier's master airway bill to CBP.
   'There's certainly a strong sense of urgency on this whole issue,' said Michael Mullen, executive director of the Express Association of America. 'I think people really want to test out what's in the realm of the possible.'
   Mullen said there have been no discussions yet on what the end state would be other than a general sense that any rule would have to be codified in some way if it is to become a permanent change.

Plugging The Gap. Meanwhile, DHS has instituted several more immediate precautions, including an indefinite ban on air cargo from Yemen and Somalia. But the announcement that all shipments of concern are now automatically placed on hold and examined upon arrival, implies two contradictory things:
   ' A new security measure was implemented to demonstrate to the public that the government is responsive when in fact the same method has been in place for years.
   ' The air cargo data wasn't routinely scrubbed for anomalies.
   The international freight transportation community has always assumed air cargo was subject to the same risk rating as freight moved by ocean and cross-border surface modes.
   On the maritime side, vessel operators must transmit the manifest 24-hours prior to loading containers at a foreign port. CBP also operates the Container Security Initiative, which is designed to push the borders out to foreign ports for pre-departure inspections. Small teams of Customs officers are stationed in 58 ports through bilateral agreements where they use risk analysis of shipping data to identify a fraction of suspicious U.S.-bound volume and make requests for automated scans by local authorities. Congress has questioned the effectiveness of the program because less than 1 percent of boxes are inspected overseas.
   CBP officials maintain the air shipment data has always been effectively plugged into its Automated Targeting System, but that no infrastructure exists at overseas airports as it does at ocean ports to hold a shipment for inspection. Until the Yemen parcel bomb plot, the focus was on stopping a nuclear or radiological device that could be used in an attack, or traditional contraband like drugs, from being smuggled by plane into the country. Now the focus has expanded to stopping attacks on aircraft and any resulting collateral damage on the ground.
   The fact that data mining based on the manifest is of questionable value for risk analysis purposes, given the unreliable nature of the document, could explain why the agency might feel less compelled to pay attention to screening inbound air cargo information. In fact, TSA wasn't much interested in the data for its purposes ('Picking up the pace,' www.AmericanShipper.com/web).
   Customs last year implemented a rule, known as the Importer Security Filing (ISF) or '10+2,' requiring importers to electronically transmit advance data about their ocean shipments because of concerns that manifest data is not very reliable or detailed enough. Part of the problem is that the information on the manifest comes from third parties and cannot be verified by the carriers.
   Bersin, in his Senate testimony, said CBP's maritime risk-management strategy serves as a good template for identifying threats, but it needs to be customized for the air cargo environment.
   CBP officials have insisted for years that ISF is only being used for maritime container security and they have no plans to apply it to air cargo, while at the same acknowledging it would be a natural extension for ISF at some future point. Their position stemmed from a desire to focus on the difficult implementation of a controversial rule within the trade community without causing further distraction and to make sure they got the program working well before taking on a bigger scope.
   Many air cargo industry officials don't want to see ISF and air cargo security in the same sentence, given the amount of work done by importers to compile shipment origination data from their overseas suppliers before vessel loading. Although airlines are willing to share advance data with CBP under the policies being considered, they fear that requiring their customers to feed data to the government could damage the industry's expedited value proposition as shipments wait for information to catch up to them.
   Pistole told the Senate Homeland Security and Governmental Affairs Committee that the U.S. government has confidence that known shippers, usually large companies with a track record of regular shipping activity, have safeguards for ensuring the integrity of their shipments through handoff to the airlines ('Finding the sweet spot,' www.AmericanShipper.com/web). The primary challenge is individual packages originating in high-threat areas where there is not a pre-existing relationship between the carrier and shipper, and there is no government security program in place, he said.
   As part of new security measures announced by DHS in the wake of the Yemen parcel plot, international mail packages must be screened individually and certified to have come from an established postal shipper. The measure essentially forces postal authorities to segregate packages based on whether they are a regular shipper with a known address so they can proceed in accordance with appropriate screening. Individuals who walk up to the counter will fall into the high-risk category and their shipments will not be allowed on passenger aircraft.
   Pistole said TSA is studying expansion of the Certified Cargo Screening Program from the passenger aircraft arena to all-cargo carriers as well. But unless 100 percent screening becomes the law for shipments on cargo-only planes, there doesn't appear to be any rationale for such a move.
   The CCSP was developed to help shippers and airlines meet the Aug. 1, 2010 deadline to screen all parcels and freight on passenger planes without causing backlogs at airports. The mandate requires screening down to the carton, or piece, level, which led to fears that airlines would be overwhelmed if some cargo wasn't prescreened before entering their systems. Unscreened cargo must be inspected by airlines at their airport facilities, which aren't geared for peripheral activities.
   Under the voluntary program, shippers can get certified to pack shipments in a secure manner or have their certified freight forwarder deconsolidate palletized freight and check it by physical or non-intrusive means. Either party must then maintain a secure chain of custody during transport to the airport.
   Shippers who participate in CCSP incur the lowest expense because they're building in security as they pack the boxes without having to pay a third party to screen on their behalf further down the supply chain.
   TSA so far has certified 1,156 facilities, including more than 100 independent operations dedicated to inspections. Together they screen half of all cargo moving on passenger planes.
   The Airforwarders Association supports more risk-based data targeting as a better approach on the freighter side of the industry than screening everything, Executive Director Brandon Fried said in an interview.
   'That's not to say that more cargo on all-cargo flights doesn't need to be screened. It just needs to be the right cargo,' Fried said.
   Although airlines and shippers are complying with the law on domestic and outbound flights, TSA has had difficulty applying the rule to all inbound flights because of jurisdictional barriers overseas and the lack of regulatory authority over freight forwarders and shippers in contrast to air carriers. In the meantime, the agency has gradually ramped up requirements, forcing international airlines to screen more than two-thirds of shipments. Pushing airlines to do more right now would simply lead to long screening lines and disrupt commerce, according to various officials.
   Pistole said the compliance figure comes from the airlines and cannot be independently verified, but TSA officials privately indicate they are confident in the self-reporting based on their industry experience and the known capabilities of individual carriers.

'This will not be the last time in which we see a response to our adjustment by the terrorist to produce another challenge. This is the new world that we live in.'
Alan Bersin
commissioner,
U.S. Customs and Border Protection

   The best way to improve air cargo security is to push the trusted shipper model to the rest of the world so that all airlines and shippers are operating under the same standard, Pistole told lawmakers. The goal is to certify foreign governments' screening systems as adequate under U.S. law.
   TSA is working with the International Air Transport Association and the International Civil Aviation Organization to encourage and help countries that don't have adequate resources develop screening programs that adhere to international standards, including ones that involve the private sector, Pistole testified.
   Countries such as the United Kingdom, Australia, and those within the European Union have well regulated air cargo supply chains to prevent bombs on aircraft and theft. TSA has access to observe the programs in action, but reaching bilateral agreements on mutual recognition is a slow and laborious process.
   IATA's initiative, called Secure Freight, aims at addressing weaknesses in countries that lack security programs. The industry group has created a security template, documents and best practices to help governments set up a security program.
   The new initiative is focused on secure shipper handling and processes to minimize the need for expensive X-ray devices. The other key objective is to get governments with existing programs to recognize the security regimes as compatible with their own practices so that transshipment and inbound cargo doesn't have to be rescreened, and airlines don't face the burden of complying with dozens of inconsistent security standards around the world.
   The lack of adequate cargo security standards was evident during a recent visit to Yemen, where the parcel bombs originated, Pistole said. Yemeni authorities are using older generation X-ray machines that don't have two-dimensional software enhancement, have neither explosive trace detection machines nor canine detectors, and only conduct very limited physical inspections.
   TSA has sent a team to Yemen to help train inspectors and also donated several explosive trace detection machines to the government, he said.
   But building a common international screening capability 'likely will take many years, perhaps decades, before most countries have established sufficient screening systems and DHS has been able to review them in enough detail to certify them,' Stephen Heifetz, who until last April was deputy assistant secretary for policy development at DHS, wrote in a prescient article published about one month before the parcel bomb plot. Now a partner in the Washington office of Steptoe & Johnson, he added it will take DHS a long time to set up an auditing program for foreign facilities.
   The best form of security in the short term, Heifetz said in the fall issue of the Airfowarders Association's magazine, is to develop a risk rating system like the one used for maritime cargo with advance importer data. Without such a system in place for inbound air cargo, he warned, industry could face draconian rules in the event of a terrorist incident involving the air cargo supply chain.
   He called on DHS to add some data points to those already collected and collect the data earlier.
   A strong risk-assessment system, using better data and algorithms for risk-rating cargo, could be implemented in a couple of years, saving time and money, and providing equal or better levels of security than trying to validate the security levels of overseas freight stations, he said.
   Writing in the New York Times a few days after the Yemen parcel bomb plot was foiled, Heifetz suggested that Congress made 'the perfect enemy of the good' by passing the 2007 mandate to physically screen all cargo on passenger planes, which distracted TSA from developing a risk assessment tool for air cargo or working with CBP on one.
   'The only practical way to increase the security of inbound air cargo is to rely on a risk rating system rather than a physical screening system,' especially since almost three-quarters of air cargo is moved by freighters, he said.
   The U.S. government and air cargo industry should require different standards of security for shipments originating in high-risk markets and transshipped between carriers, according to Brian Clancy, managing director of Logistics Capital & Strategy, a financial and strategic advisory firm based in Arlington, Va.
   'The ability to introduce a package that has a threat is likely to be easier in a high-threat country than in low-risk country, which has more security to begin with. But the biggest challenge is that no system is ever perfect. One hundred percent security is never possible because the resources needed to achieve that is a non-linear curve ' it goes up at an accelerating rate' to fill the last gaps.
   'So a partitioning strategy to me is a logical one. Every airport in a country and every country get ranked' by their security protocols, said Clancy, who recently split from MergeGlobal.
   And cargo that flies on a dedicated plane with custodial control, such as one operated by FedEx or UPS, follows one level of security versus an interline shipment subject to one or more handoffs.
   The packages from Yemen, Clancy pointed out, went from an agent through an interline passenger airline service to Dubai before they entered the express carriers' systems.
   'Interline handoffs in high-threat markets are probably the most vulnerable points in the U.S. air import network,' Clancy said.
   Even if there is adequate security in a high-risk market there should be a second layer of scrutiny applied when the cargo gets to a transshipment hub, he added.
   And global shippers, who move high-value products through tightly controlled supply chains with a small number of handoffs and belong to programs like the Customs-Trade Partnership Against Terrorism, would have shipments go through the fast lane compared to the high-inspection, slow lane for infrequent and unknown shippers.
   'The trick is to bifurcate the packages based on who is tendering them and where they're tendering them. If they're tendering in a high-threat market as an unknown shipper walking up to a franchise store front ' that will have a different set of rules,' such as embargoing it for two or three days until all the manifest information can be collected and rated for risk.
   'It slows things down, but that part of the market is such a small part of their business that it's not a financial problem' for cargo carriers to impose the rules and risk losing those customers.
   Pistole predicted express carriers and other cargo airlines are likely to avoid countries that have serious security gaps.
   'I think what we'll probably see from a private sector risk model is that they may not pick up packages from countries' assessed as high risk, he said.

Adapting To Terrorists. CBP leaders, past and present, insist the agency took appropriate steps to deal with concrete threats and adjusted its aviation security strategy as dictated by intelligence.
   Prior to the attempted attack on U.S.-bound freighters, the primary threat to commercial aircraft was considered to come from the passenger side in the form of explosives in baggage or carried by a suicide bomber, or terrorists commandeering a plane and crashing it into a building as happened on Sept. 11, 2001.
   'Now we have intelligence, an act and a continuing threat stream, so we have a responsibility to act,' said Jayson Ahern, who until last December was acting commissioner of CBP and now is a principal for risk management consultancy The Chertoff Group.
   Asked why DHS didn't anticipate that freighters themselves would become terrorist targets, Ahern responded the key is to look ahead to the new threat.
   'What we did or didn't do in the past is irrelevant,' he said.
   Bersin, interviewed in his office at CBP headquarters, compared the current initiative to the way DHS responded to the failed attempt by underwear bomber Umar Farouk Abdul Mutallab to destroy a Northwest Airlines jet last Christmas.
   In late November, DHS announced that it had met its goal of prescreening all passenger data for flights originating in or bound for the United States. Under the Secure Flight program, TSA matches every name, date of birth and gender against terrorist watchlists before passengers receive their boarding pass. Most passengers are cleared to print boarding passes at home or at a self-serve kiosk. Individuals found to match watchlist parameters are subject to secondary screening, a law enforcement interview or prohibition from boarding an aircraft, depending on the specific case.
   Airlines previously had responsibility for checking passengers against the government watchlists.
   'In the same way we moved to pre-departure information after Dec. 25 on passenger, so we move to pre-departure with regard to cargo after this incident,' Bersin said.
   'Look, this is an ongoing process of reacting to counter-terrorist threats. The nature of the threat changes and this will not be the last time in which we see a response to our adjustment by the terrorist to produce another challenge. This is the new world that we live in.'
Upcoming FreightWaves Events
Compliance

Brokerage Compliance Symposium

The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.

October 26, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Awards

F3 Awards Dinner

The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.

October 26, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
FreightTech

F3: Future of Freight Festival

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

October 27, 2026 – October 28, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Compliance Brokerage Compliance Symposium Oct 26 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now
Awards F3 Awards Dinner Oct 26 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now
FreightTech F3: Future of Freight Festival Oct 27 – Oct 28 • The Signal at Chattanooga Choo Choo • Chattanooga, TN

Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now