Customs Audit Preparation and Response
CBP audits can span 5 years of entries — how to prepare and what to expect during a focused assessment
- Customs Audit Preparation and Response
- Internal Compliance Reviews
- Responding to a CBP Request for Information
- How a Focused Assessment Actually Unfolds
- Worked Example: An Internal Review That Averted a Penalty
Customs Audit Preparation and Response#
CBP conducts focused assessments targeting specific compliance areas: classification, valuation, marking, FTA claims, or AD/CVD. They typically review 3-5 years of entries and can impose penalties of 20-40% of lost revenue. Companies with prior disclosure programs fare much better — voluntary disclosure before an audit reduces penalties by 50-75%.
Internal Compliance Reviews#
Run your own audit annually. Pull 50-100 random entries and verify: correct HTS classification, proper valuation, accurate country of origin, valid FTA certificates, and proper marking. If you find errors, file prior disclosures immediately. Finding your own mistakes before CBP does is always cheaper.
Responding to a CBP Request for Information#
When CBP sends a CF-28 (Request for Information) or CF-29 (Notice of Action), respond within 30 days. Late responses escalate to formal investigations. Engage a customs attorney if the inquiry involves significant duty exposure. Never ignore CBP correspondence — it never gets better with time.
How a Focused Assessment Actually Unfolds#
A CBP focused assessment moves through distinct phases, and understanding each one helps an importer respond appropriately rather than either panicking or under-reacting. It typically opens with a pre-assessment survey, where CBP requests general information about your import volume, internal controls, and recordkeeping systems to decide whether a full audit is warranted and, if so, which compliance areas to target. If the survey raises concerns, CBP moves to the assessment phase itself: a team of auditors, often including a National Import Specialist for complex classification questions, requests a statistically valid sample of entries — commonly 30-60 transactions pulled from the prior 3-5 years — and reviews each one against your internal records, supplier documentation, and the declarations actually filed. Auditors are testing not just whether a handful of entries were correct, but whether your internal control environment reliably produces correct declarations at scale; a company with strong documented procedures that catches its own occasional errors is treated very differently from one with no internal review process at all, even if the raw error rate looks similar. The assessment concludes with a report finding either an acceptable risk rating, a required corrective action plan, or a referral for penalty action and, in serious cases, revenue recovery going back through the full audit period.
Worked Example: An Internal Review That Averted a Penalty#
Consider a mid-size industrial parts importer with roughly $6 million in annual import value across 40 SKUs. During a routine internal compliance review — conducted proactively, not in response to any CBP inquiry — the compliance manager discovers that eight SKUs have been classified under a heading that made sense five years ago but no longer reflects a supplier component change made three years back, when a supplier switched to a different bearing material. The misclassification resulted in underpaid duty of approximately 4.5 percentage points on those SKUs, totaling an estimated $187,000 in underpaid duty across the affected period. Rather than waiting to see if CBP would catch it, the company files a prior disclosure — voluntarily notifying CBP of the error, tendering the underpaid duty plus interest, and documenting the root cause and corrective action taken (updated classification, revised supplier-change SOP requiring classification re-review on any material substitution). Under CBP's prior disclosure framework, this converts what could have been a penalty case carrying fraud or negligence exposure — potentially 20-40% of the lost revenue in addition to the duty owed — into a duty-plus-interest settlement with no penalty assessed at all, because the disclosure was voluntary and complete before CBP initiated any inquiry.
Common Mistakes That Turn a Routine Audit Into a Penalty Case#
The most damaging mistake is treating a CF-28 request for information as a low-priority administrative task rather than the opening move of a potential audit — a late or incomplete response signals weak internal controls and often triggers a broader inquiry than the original request would have. A second mistake is responding to CBP requests without first conducting an internal review of the entries in question, which risks submitting information that is itself inaccurate or incomplete, compounding the original issue. Third, many companies discover errors during a CBP audit that they could have found and disclosed themselves months or years earlier through routine internal review — and the penalty exposure is materially different depending on who found the error first, since a company that self-discovers and discloses is treated far more leniently than one CBP catches unprompted. Fourth, some importers assume that using a licensed customs broker shifts legal responsibility for classification and valuation accuracy to the broker — it does not; the importer of record bears ultimate legal responsibility for the accuracy of every entry regardless of who prepared the paperwork, a distinction that surprises many first-time audit targets.
Building an Internal Compliance Program That Holds Up#
A credible internal compliance program is the single biggest factor in how CBP treats any errors it finds, because it demonstrates the "reasonable care" standard the importer is legally required to exercise. At minimum, this means an annual self-audit pulling a random sample of entries across all major SKUs and verifying classification, valuation, origin, and marking against current documentation — not just relying on whatever classification was assigned when a product first started shipping years ago. It also means a documented process for reviewing classifications whenever a product, material, or supplier changes, since that is exactly the kind of drift that produces the multi-year, multi-SKU errors CBP audits are designed to catch. For businesses managing dozens or hundreds of active SKUs across multiple suppliers, keeping this review current by hand becomes difficult at scale — a trade intelligence platform like AskBiz that maintains a live record of HTS codes, sourcing countries, and applicable trade-remedy actions per SKU makes it far easier to spot when a product's classification basis has become stale, catching the kind of gap that turned into a $187,000 exposure in the example above before it accumulates across years of entries.
People also ask
What is the business impact of customs audit preparation and response?
CBP audits can span 5 years of entries — how to prepare and what to expect during a focused assessment
What's the biggest risk with customs audit preparation and response?
CBP conducts focused assessments targeting specific compliance areas: classification, valuation, marking, FTA claims, or AD/CVD. They typically review 3-5 years of entries and can impose penalties of 20-40% of lost revenue. Companies with prior disclosure programs fare much better — voluntary disclosure before an audit reduces penalties by 50-75%.
How should a business act on this?
When CBP sends a CF-28 (Request for Information) or CF-29 (Notice of Action), respond within 30 days. Late responses escalate to formal investigations. Engage a customs attorney if the inquiry involves significant duty exposure. Never ignore CBP correspondence — it never gets better with time.
Our team combines expertise in data analytics, SME strategy, and AI tools to produce practical guides that help founders and operators make better business decisions.
Get Real-Time Trade Intelligence
AskBiz monitors global trade conditions 24/7. Track tariffs, currencies, supply chains, and compliance requirements. Start free — no credit card required.
Connects to Shopify, Xero, Amazon, QuickBooks, Stripe & more in minutes