Framework overlap

Does PCI P2PE cover Authorised Economic Operator (AEO) Programmes?

You hold PCI P2PE and have been told to do Authorised Economic Operator (AEO) Programmes. Here is how much overlaps, control by control.

28% of Authorised Economic Operator (AEO) Programmes you already have

PCI P2PE already covers about 28% of Authorised Economic Operator (AEO) Programmes, leaving 26 of 36 controls as genuinely new work.

Already covered 1 Likely covered 9 New work 26

What is genuinely new work

Nothing in PCI P2PE reaches these. This is the list to scope.

AEO-1
AEO programme eligibility and legal basis
AEO-10
Security training and awareness
AEO-12
Crisis management and incident recovery
AEO-13
Self-assessment and internal audit
AEO-14
Customs procedures and declaration accuracy
AEO-15
Mutual recognition arrangements
AEO-16
AEO validation and re-validation
AEO-17
Notification of changes
AEO-18
Trade facilitation benefits realisation
AEO-19
Suspension, withdrawal and revocation
AEO-20
AEO governance and accountability
AEO-21
Customs broker and forwarder oversight
AEO-22
Sanctions and restricted party screening
AEO-23
Documentation accuracy and tariff classification
AEO-3
Commercial and transport records system
AEO-6
Cargo security and conveyance integrity
AEO-7
Business partner security
AEO-8
Personnel security
AEO-9
Information security and IT systems
P1-S3
Outbound inspection
P2-S2
Security standards
P2-S4
Technology utilization
P2-S5
Communication
P2-S6
Trade facilitation benefits
P3-S1
Inter-agency cooperation
P3-S2
Single window facilitation
Show the 10 you already have
P1-S2
Risk management
AEO-11
Risk management and threat assessment
AEO-2
Customs compliance record
AEO-4
Financial solvency
AEO-5
Premises security and safety standards
P1-S1
Advance electronic information
P1-S4
Mutual recognition (Customs-to-Customs)
P2-S1
Partnership programme (AEO)
P2-S3
Authorization and validation
P3-S3
Data sharing

How this is calculated

Already covered means a mapping runs from a control in PCI P2PE to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition