Import Security Risk Analysis: EU Rules
Quick answer
Import security risk analysis in the European Union (EU) requires businesses to submit an Entry Summary Declaration (ENS) ahead of goods arriving at the customs office of first entry. This process enables customs authorities to assess security risks and, if necessary, take immediate action such as prohibiting loading or entry of goods. The rules apply to all operators involved in importing goods into the EU, with specific provisions for maritime and air cargo, multi-port journeys, and related sanitary and phytosanitary checks [1][2][3].
Key takeaways
- Importers and carriers must lodge an Entry Summary Declaration (ENS) within prescribed time limits before goods arrive in the EU.
- Customs authorities conduct risk analysis based on the ENS to identify security threats before goods enter the EU customs territory.
- For containerised maritime cargo, risk analysis must be completed within 24 hours of ENS receipt.
- Immediate action, including “Do Not Load” notifications, can be issued if a serious security threat is detected.
- For goods arriving by air, high-risk consignments require screening before loading onto aircraft bound for the EU.
- Multi-port or airport journeys within the EU require a single ENS at the first point of entry, with risk analysis results shared with subsequent ports.
- Sanitary and phytosanitary checks complement security risk analysis and must be risk-based and proportionate.
- Customs duties and import regulations remain applicable alongside security risk measures.
Who Needs to Know About EU Import Security Risk Analysis?
EU import security risk analysis applies primarily to importers, carriers, freight forwarders, and customs representatives involved in bringing goods into the EU customs territory. Any business or entity lodging an Entry Summary Declaration (ENS) must comply with the relevant rules to enable customs authorities to perform risk assessments before goods arrive [1:1].
The ENS is a mandatory customs declaration that provides advance information about incoming goods. It allows customs authorities to identify potential security threats early and decide whether immediate action is necessary. The obligation to lodge an ENS and cooperate with customs risk analysis applies regardless of the mode of transport—sea, air, or other means—though specific rules vary by transport mode [1:2][2:1].
Businesses operating within the EU single market must ensure they have a valid Economic Operators Registration and Identification (EORI) number, which is required for customs declarations including the ENS. The ENS must be lodged with the customs office of first entry into the EU, which could be a seaport, airport, or land border crossing, depending on the point of arrival [1:3].
The Role of the Entry Summary Declaration (ENS)
The Entry Summary Declaration (ENS) is the cornerstone of import security risk analysis in the EU. It must be lodged within the time limits established by Delegated Regulation (EU) 2015/2446 before the goods arrive at the customs office of first entry [1:4]. The ENS contains detailed information about the goods, consignor, consignee, transport means, and route.
Upon receipt of the ENS, customs authorities carry out risk analysis to detect potential threats to security and safety. For containerised cargo arriving by sea, the risk analysis must be completed within 24 hours of ENS receipt [1:5]. If the risk analysis reveals serious threats, customs authorities notify the declarant and, if different, the carrier, that the goods must not be loaded onto the vessel or aircraft [1:6][2:2].
In practice, this means EU businesses importing goods must ensure timely and accurate submission of the ENS to avoid delays or refusals at the border. Failure to lodge the ENS on time or provide complete information can result in customs authorities taking prohibitive action, including refusing entry or unloading of goods [1:7].
Specific Rules for Maritime and Air Cargo
The EU’s import security risk analysis framework differentiates between maritime and air cargo due to their distinct security risks and operational characteristics.
Maritime Cargo
For containerised maritime cargo, the customs authorities must complete risk analysis within 24 hours of receiving the ENS [1:8]. If a serious threat is detected, customs immediately notify the declarant and carrier that the goods are not to be loaded onto the vessel. This notification must occur promptly after risk detection and within the 24-hour timeframe [1:9].
This rule ensures that potentially dangerous goods are intercepted before entering the EU customs territory, enhancing maritime security. The customs office of first entry is responsible for taking prohibitive action upon arrival if the threat persists [1:10].
Air Cargo
For air cargo, if customs authorities have reasonable grounds to suspect a serious aviation security threat, they must notify the declarant or the person who submitted the ENS details, and, if different, the carrier, that the consignment requires screening as High Risk Cargo and Mail. This screening must comply with the standards set out in Commission Decision C(2010) 774 and Regulation (EC) No 300/2008 before loading on an aircraft bound for the EU [2:3].
Following notification, the declarant must inform customs whether the consignment has already been screened or provide all relevant screening information. Risk analysis is only completed after this information is provided [2:4].
If the risk analysis confirms a serious threat, customs notify that the goods must not be loaded, and prohibitive action is taken upon arrival [2:5].
Immediate Action and “Do Not Load” Notifications
When customs authorities identify a security risk of such seriousness that immediate intervention is required, they issue a “Do Not Load” notification to the declarant and carrier (if different) via the electronic system referenced in Article 182 of Commission Implementing Regulation (EU) 2015/2447 [1:11][2:6].
This notification prohibits the loading of the goods onto the vessel or aircraft bound for the EU. The notification must be issued immediately after the detection of the risk and within the statutory time limits (24 hours for maritime containerised cargo) [1:12].
Upon arrival, the customs office of first entry must take appropriate prohibitive action, which may include seizure, detention, or refusal of entry of the goods [2:7].
For EU businesses, this means that compliance with ENS requirements and timely communication with customs authorities is crucial to avoid costly delays or rejection of shipments. Companies should maintain robust internal procedures for ENS submission and monitor notifications from customs systems to respond promptly to any “Do Not Load” orders.
Multi-Port/Airport Journeys Within the EU
The EU customs rules recognise that vessels or aircraft may call at multiple ports or airports within the EU customs territory without leaving it. In such cases, the risk analysis and ENS requirements are adapted to avoid duplication and ensure effective security management [1:13].
For all goods carried by a vessel or aircraft calling at multiple EU ports or airports, a single ENS must be lodged at the first port or airport of entry into the EU customs territory [1:14].
The customs authorities at this first entry point conduct risk analysis for all goods on board. Additional risk analyses may be performed at subsequent ports or airports where goods are discharged [1:15].
If a serious threat requiring immediate intervention is identified, the customs office at the first entry port or airport must take prohibitive action and communicate the risk analysis results to subsequent ports or airports [1:16].
At subsequent ports or airports, customs procedures under Article 145 of the Union Customs Code apply for goods presented there [1:17].
For EU businesses, this means that the ENS lodged at the first entry point covers the entire journey within the EU customs territory, simplifying compliance. However, companies must be aware that customs authorities at subsequent ports may still conduct further checks or interventions based on updated risk analyses.
Sanitary and Phytosanitary Checks: A Related Consideration
While import security risk analysis focuses on safety and security threats, sanitary and phytosanitary (SPS) checks address health risks related to plants, animals, and food products. These checks are conducted in a risk-based, proportionate, and non-discriminatory manner to ensure compliance with EU health standards [3:1].
EU businesses importing goods subject to SPS controls must ensure that products meet the sanitary and phytosanitary requirements of the EU. Import checks may be conducted without undue delay and based on an assessment of risk factors such as origin, product type, and previous compliance history [3:2].
Where non-compliance is detected during SPS checks, the actions taken must be proportionate and not more trade-restrictive than necessary to achieve the EU’s appropriate level of protection [3:3].
In practice, companies should coordinate customs risk analysis with SPS compliance to avoid delays or refusals at the border. This includes providing accurate documentation and cooperating with relevant authorities.
Impact on Customs Duties and Other Import Regulations
Import security risk analysis operates alongside other customs obligations, including the classification of goods, customs duties, and trade defence measures.
Goods imported into the EU are classified according to the Combined Nomenclature (CN) and Common Customs Tariff, as established by Council Regulation (EEC) No 2658/87 and amended by Commission Implementing Regulations such as (EU) 2023/2364 and (EU) 2022/1998 [4][5]. Proper classification affects the applicable customs duties.
Customs duties are generally ad valorem and may vary depending on trade agreements, autonomous tariff rates, or specific countervailing duties imposed on certain products from specific countries [4:1][6][7].
For example, definitive or provisional countervailing duties may apply to certain imports, subject to conditions such as presentation of valid commercial invoices with specific declarations [6:1][7:1].
The carbon border adjustment mechanism (CBAM) also imposes requirements on importers, including authorisation and reporting obligations, which customs authorities monitor alongside security risk analysis [8].
EU businesses must ensure compliance with all relevant customs regulations in addition to import security risk analysis requirements. This includes correct tariff classification, duty payments, and adherence to trade defence measures.
FAQ
What is DPL screening?
DPL screening refers to the process of screening shipments against Denied Party Lists (DPL) to ensure that goods are not traded with prohibited or restricted entities. In the context of EU import security risk analysis, dpl screening helps identify consignments that may pose security risks due to associations with denied parties. It is a key component of broader risk management and compliance efforts [1:18][2:8].
What is a DPL?
A DPL, or Denied Party List, is a list of individuals, companies, or entities that are subject to trade restrictions or prohibitions due to security, legal, or regulatory reasons. These lists are maintained by governments and international organisations to prevent trade with parties involved in illegal or high-risk activities. EU customs authorities use DPLs as part of their risk analysis to prevent illicit trade [1:19][2:9].
What is DPS screening?
DPS screening stands for Denied Party Screening, a compliance process whereby shipments, customers, or business partners are checked against Denied Party Lists to identify restricted entities. DPS screening is an essential tool for EU businesses to comply with customs and trade security regulations, including import security risk analysis requirements [1:20][2:10].
What is the Descartes denied party screening solution?
The Descartes denied party screening solution is a commercial software tool that automates the process of screening trade parties against multiple Denied Party Lists. It helps businesses ensure compliance with trade restrictions and import security requirements by flagging potential matches before goods enter the EU market. While not mandated by EU law, such solutions support dpl screening practices necessary for compliance with EU import security risk analysis [1:21][2:11].
This article provides a general overview of EU import security risk analysis and related compliance obligations. Businesses should consult qualified legal counsel or their national competent authority for advice tailored to their specific circumstances.
Sources
[3 Sanitary and phytosanitary matters, Article 11](https://circabc.europa.eu/d/d/workspace/SpacesStore/e880e96b-cd64-4c59-b594-65d85379b0ac/3 Sanitary and phytosanitary matters.pdf)