Trade Compliance

Compliance Isn't Binary Anymore: 5 Takeaways from ICPA Grapevine

Grant Sernick
Grant Sernick
September 30, 2026
-
5
min read
Compliance Isn't Binary Anymore: 5 Takeaways from ICPA GrapevineCompliance Isn't Binary Anymore: 5 Takeaways from ICPA Grapevine

At the CBP symposium held the week before the 2026 ICPA Global Trade Pathways Conference in Grapevine, Texas, the message from the agency was not subtle. Speaker after speaker landed on the same word: enforcement. Across the conference itself, the hallway conversations kept circling a quieter admission. Nobody is fully compliant anymore, and most teams cannot say how exposed they actually are.

Those two facts are related, and together they change what the trade compliance job is.

On September 24, 3rdwave VP of Sales and Marketing Grant Sernick unpacked what he heard in Texas in a webinar titled Compliance Isn't Binary Anymore: 5 Takeaways from ICPA Grapevine. 3rdwave builds a supply chain execution and trade compliance platform for importers and exporters, including the Entry Verification tools that reconstruct what a customs entry should have said and compare it against what the broker filed. Grant spends most of his year talking with the people who own import risk, and that is the lens for everything below.

Here are the five takeaways that matter most for how you do your job, and what each one asks of you next. The full recording is below.

1. CBP Said the Quiet Part Out Loud

Grant opened in 2010. Rules changed slowly. The playbook with your broker was well understood, and if CBP ever came in, they gave you credit for running it. The agency's view inside any one importer was limited, because analysis on ACE was expensive and CBP was selective about whom it pursued.

That produced a comfortable conclusion in a lot of boardrooms: we have process, we have never been audited, therefore we are fine. Grant's challenge to that logic was the sharpest line of the hour.

"So were we compliant? Maybe. But perhaps it was also that errors were hard to find... And the conclusion was, well, maybe we were confusing low rates of detection with high rates of compliance. Those are not the same thing."

The symposium removed any doubt about which one it was. Grant pointed to CBP Commissioner Rodney Scott's description, in responses to the Senate Finance Committee, of a "multi-layered enforcement posture across the international cargo lifecycle," meaning upstream and downstream of the border, not just at it. In practice that means more capacity through hiring, more analysis through AI applied to large data sets, and more consequence when the agency decides to look at you.

"They're going to be able to see more. They're going to be able to connect more information together and act earlier in the process. These are not good things as it relates to being responsible for managing trade risk within an organization."

What it asks of you: stop treating the absence of an audit as evidence of compliance. The question now is what CBP will find when it looks.

2. Flawless Is Off the Table. Defensible Is the Standard.

Grant got into trade compliance in 2015 and remembers finding it impenetrable. Looking back, he called that era "categorically simple" compared to today.

The reason is Chapter 99 of the Harmonized Tariff Schedule. The temporary-provisions chapter that used to be arcane and rarely touched now runs 818 pages and carries the weight of active trade policy. One product no longer needs one classification. It needs classification, origin, content, value, every applicable measure, and the exceptions and effective dates that decide whether a given layer applies to a given shipment.

"If you want to be compliant and try to get that binary to a one, you will quickly understand that that's virtually impossible to achieve."

That is not a counsel of despair. It is a change in the math. One wrong upstream fact distorts several tariff layers across every entry it touches, and compliance programs built for one code per product have not kept up.

"We do have to understand we are never getting to fully compliant, and that is going to change the calculus and the way we have to think about compliance holistically."

What it asks of you: retire "are we compliant?" as the question you report on. Replace it with "where are we exposed, and can we defend it?"

3. Risk Is a Spectrum, Not a Switch

If perfect is unreachable, the job becomes choosing a position. At one end of Grant's spectrum is no program at all: maximum uncertainty, maximum risk. At the other is full control, reachable only with tens or hundreds of millions of dollars of investment.

"It's very unreasonable to be totally unmanaged, and it is also equally unreasonable to be fully controlled and defensible because likely it is too expensive to do."

So the work happens in the middle, and occupying the middle deliberately looks different from drifting there. Grant listed what a managed position requires: better data, testing across the whole entry population rather than a sample, correction fast enough to land inside the 10-day window rather than in a quarterly review, and evidence recorded systematically so the position can be defended if challenged. (For a practical walk-through of that correction window, see 7 Steps to Catch Your Entry Errors Before CBP Does.)

The legal requirement, as CBP sees it, is still binary. Your risk position is not. Knowing where you sit, and being able to explain why, is the job.

What it asks of you: choose your position on purpose, and build the evidence trail that lets you defend it.

4. Your Broker's Stacking Errors Land on You

Getting the 10-digit HTS code right is hard, and plenty of companies are throwing AI at it. But classification is now one input among many. Applying Chapter 99 correctly to a properly classified product takes five domains of information: product facts and bills of material; origin and production, down to where steel, aluminum, or copper was melted and poured or smelted and cast; transaction facts like entry date, value, and program; rule inputs, including which headings apply, their effective dates, exclusions, and stacking order; and the evidence, such as mill certificates and supplier declarations, that substantiates the rest.

Your broker typically has the transaction facts. The rest is partial, variable, or missing. Grant voiced the broker's side honestly.

"I never have all of the things I need and I'm doing hundreds or thousands of entries a week. And if I had to contact the importer of record for all of these elements in order to affect a compliant entry, I just would never be able to get anything done."

That is a reasonable position for a broker to hold. It is also why the conclusion is unavoidable.

"If they're submitting entries without the superset of information that is required in order to ensure that the appropriate Chapter 99s are being applied and in the appropriate order, then the conclusion needs to be that some of the entries are wrong. It has to be that way because there is no way they could get it right."

The liability for those entries sits with the importer of record, not the broker. And Grant added a harder point: a lot of that information is probably not sitting with you either.

What it asks of you: map which of the five domains you hold, which your broker receives, and where the gaps are. Every gap is an entry that may be wrong today.

5. The Role Moves Up or It Disappears

In the old world, a compliance manager was responsible for technical correctness and for keeping the process nominally in control. Auditing was tedious, it slid to the bottom of the list, and the environment forgave that. The new job is risk advisor to senior leadership.

"The senior leaders do not understand the trade environment. They do not understand the regulations... What they know is what you tell them."

Grant was blunt about what follows. In 2010, leadership being unaware of trade risk was defensible, because material exposure was rare. In 2026 it is not.

"If your senior leadership is ignorant to the trade risk, then you as a trade professional are not doing your job."

You cannot advise on a risk you cannot size. Being credible at the leadership table means knowing what should have been filed, what the broker actually filed, and what CBP received, across every entry, and being able to separate transactional failures from procedural ones. Grant's view is that this is only possible systematically. Spreadsheets and quarterly samples cannot produce evidence an executive team can act on.

This is the problem 3rdwave was in Grapevine to talk about. Grant described the platform as the missing control layer: consolidate documents, master data, and broker filings; reconstruct the expected entry and tariff stack; test every entry against configurable rules; rank exceptions by risk; and correct them inside a workflow that preserves the evidence. 3rdwave will run it on your own broker data and entry packets as a free trial, so the first conversation with leadership can start with a real number.

What it asks of you: get a system that tells you the size of the risk before the audit does, and use it to educate leadership before CBP does.

The Takeaway for Import Compliance Leaders

Compliance used to be a 1 or a 0. It is now a position on a spectrum, held whether or not you have mapped it. CBP is hiring, targeting with AI, and openly intent on finding importers who got it wrong. Chapter 99 makes flawless unreachable. Your broker is filing with a subset of the facts, and the liability is yours. The durable answer is to know the position, defend the evidence, and tell leadership the truth before someone else does.

Watch the full session above. To see how much risk is sitting in your own entries, connect with our team or email freetrial@3rdwave.co. And if you were in Grapevine and read the room differently, reach me at grant@3rdwave.co or connect with me on LinkedIn. I would like to hear it.

Contact Us

3rdwave violet logo
Thanks! We’ve received your information and one of our product experts will be in touch soon.
In the meantime, we invite you to check out our latest content.
Oops! Something went wrong while submitting the form.

Subscribe Now

3rdwave violet logo
Thanks! We’ve received your information and one of our product experts will be in touch soon.
In the meantime, we invite you to check out our latest content.
Oops! Something went wrong while submitting the form.
Simply the Best Platform for International Shippers
Hey Control Freak!
Sign up to receive blog posts and webinar invites on all things supply chain.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

© 3RDWAVE 2023. All Rights Reserved.