forked from intuitem/ciso-assistant-community
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathitar-compliance-program-guidelines.yaml
5862 lines (5861 loc) · 317 KB
/
itar-compliance-program-guidelines.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
urn: urn:intuitem:risk:library:itar-compliance-program-guidelines
locale: en
ref_id: ITAR-Compliance-Program-Guidelines
name: ITAR Compliance Program Guidelines
description: "The guidelines contained in this document are intended to provide an\
\ overview of an effective compliance program and an introduction to defense trade\
\ controls, including information on the laws and regulations the U.S. Department\
\ of State, Bureau of Political-Military Affairs, Directorate of Defense Trade Controls\
\ (DDTC), administers. These defense trade controls are contained in the Arms Export\
\ Control Act (AECA) (22 U.S.C. \xA7 2751 et seq.) as amended, and the International\
\ Traffic in Arms Regulations (ITAR), Title 22 of the Code of Federal Regulations\
\ in parts 120-130, both of which are authoritative on defense trade controls. \n\
version 09/15/2023\nLink : https://www.pmddtc.state.gov/ddtc_public/ddtc_public?id=ddtc_kb_article_page&sys_id=4f06583fdb78d300d0a370131f961913 "
copyright: Directorate of Defense Trade Controls
version: 1
provider: Directorate of Defense Trade Controls
packager: intuitem
objects:
framework:
urn: urn:intuitem:risk:framework:itar-compliance-program-guidelines
ref_id: ITAR-Compliance-Program-Guidelines
name: ITAR Compliance Program Guidelines
description: "The guidelines contained in this document are intended to provide\
\ an overview of an effective compliance program and an introduction to defense\
\ trade controls, including information on the laws and regulations the U.S.\
\ Department of State, Bureau of Political-Military Affairs, Directorate of\
\ Defense Trade Controls (DDTC), administers. These defense trade controls are\
\ contained in the Arms Export Control Act (AECA) (22 U.S.C. \xA7 2751 et seq.)\
\ as amended, and the International Traffic in Arms Regulations (ITAR), Title\
\ 22 of the Code of Federal Regulations in parts 120-130, both of which are\
\ authoritative on defense trade controls. \nversion 09/15/2023\nLink : https://www.pmddtc.state.gov/ddtc_public/ddtc_public?id=ddtc_kb_article_page&sys_id=4f06583fdb78d300d0a370131f961913 "
implementation_groups_definition:
- ref_id: DDTC
name: DDTC Suggestions
description: DDTC Suggestions
- ref_id: 7C
name: Sample Audit Checklists
description: Sample Audit Checklists
requirement_nodes:
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1
assessable: false
depth: 1
ref_id: ELEMENT 1
name: MANAGEMENT COMMITMENT
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1
ref_id: ELEMENT 1A
name: Developing and Generating Support for a Culture of Compliance
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:1
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a
description: Management commitment is one of the most important factors in creating
a deep-rooted culture of ITAR compliance within organizations. While robust
management commitment alone is insufficient to ensure compliance with all
relevant U.S. export control laws and regulations, it is essential for fostering
a proactive compliance posture.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:2
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a
description: "Management includes not only senior management, but also managers\
\ at all levels within the organization, and the most important stance management\
\ can take to engender a culture of compliance is to lead by example. Through\
\ their words and actions, management should encourage compliance and should\
\ discourage the prioritization of business or other interests over compliance.\
\ Employees should have a high level of assurance that ITAR compliance is\
\ management\u2019s greatest priority in all export-related decisions. Management\
\ should communicate to employees that they are encouraged to raise questions\
\ or concerns about compliance and potential risk areas and employees will\
\ not experience retribution or retaliation if they do so. Employees should\
\ understand that ITAR compliance is everyone\u2019s responsibility within\
\ the organization."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a
description: "To help generate support and buy-in among employees, management\
\ should incorporate compliance into employee performance plans and evaluations.\
\ Employees should be expected to think about and recommend ways to improve\
\ compliance and raise concerns when they see a possible problem, and their\
\ performance plans and evaluations should account for those expectations.\
\ Additionally, management should recognize and reward employees who speak\
\ up, even if the problem reported resulted in no specific confirmed violation,\
\ but perhaps lead to improving the organization\u2019s compliance procedures."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:4
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a
description: "In addition, management should communicate to employees that export\
\ control violations will not be tolerated and may result in disciplinary\
\ action against the employee, regardless of the employee\u2019s position,\
\ title, or performance. Management should adopt clear disciplinary procedures\
\ and consequences for addressing compliance misconduct, should enforce them\
\ consistently across the organization, and should ensure that they are proportionate\
\ to the misconduct and appropriate to deter future misconduct."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1
ref_id: ELEMENT 1B
name: Demonstrating Management Commitment Through Policies and Procedures
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b
description: "Management is ultimately responsible for ensuring its organization\u2019\
s compliance with the ITAR. Management can demonstrate its commitment to ITAR\
\ compliance by:"
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1
description: Creating and maintaining an ICP;
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1:2
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1
description: "Providing sufficient resources, including time, funding, personnel,\
\ and training, to implement and maintain an ICP commensurate with the organization\u2019\
s risk; and"
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1:3
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1
description: Creating and maintaining an Export Compliance Management Commitment
Statement.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b
name: ITAR Compliance Program
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2
description: "A critical aspect of management\u2019s effort to demonstrate its\
\ commitment to compliance with the ITAR is creating and maintaining an ICP.\
\ An effective ICP should be:"
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1
description: In writing and clearly state the organizations ITAR compliance
policies and procedures;
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1
description: "Specifically tailored to an organization\u2019s ITAR-controlled\
\ activities and its areas of risk;"
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:3
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1
description: Regularly reviewed and updated by various business departments
responsible for complying with the ITAR; and
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:4
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1
description: Fully supported by management.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:2
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2
description: When developing an ICP, management should identify areas that could
potentially pose a risk of ITAR violations and the lines of authority, e.g.,
direct, indirect, and unofficial, in those areas that can assist in preventing
ITAR violations. After an ICP is established, management should remain actively
engaged in improving the compliance program, e.g., by attending periodic ICP
resource and planning meetings at which employees can discuss any ITAR compliance
deficiencies they have identified or propose changes to enhance the ICP.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:3
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b
name: Sufficient Compliance Resources
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:3:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:3
description: "Management should provide compliance personnel with adequate resources,\
\ including the appropriate training, funding, human capital, organizational\
\ support, information technology resources, and other resources to fulfill\
\ their responsibilities and implement an effective ICP. In assessing whether\
\ such resources are adequate, management should take account of the organization\u2019\
s size, scope of operations, and overall risk profile."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b
name: Export Compliance Management Commitment Statement
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4
description: 'Another critical way to demonstrate strong management support
for ITAR compliance is to have the Chief Executive Officer, President, or
other senior executives personally sign an Export Compliance Management Commitment
Statement that is communicated to employees through all appropriate channels,
including in the opening pages of an ITAR Compliance Manual, on the corporate
website, and through periodic email reminders to all employees. The organization
should review and disseminate this statement at least annually for all employees
and, as appropriate, all contractors to read and sign. The statement should:'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: "Underscore the organization\u2019s commitment to export compliance\
\ and providing sufficient resources to ensure compliance."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: Reference the role and function of the U.S. export control system
and its importance in protecting the foreign policy and national security
of the United States.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:3
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: Affirm that no export shall be made under any circumstances that
violates or potentially violates the ITAR.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:4
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: "Emphasize the importance of employees understanding the ITAR and\
\ its impact on their job functions. Employees should also understand specific\
\ risks of non-compliance regarding an organization\u2019s activities, technologies,\
\ and export destinations."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:5
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: Communicate the importance of routine export compliance monitoring
and auditing.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:6
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: "Stress the importance of and/or the requirement to report known\
\ or suspected violations to the organization\u2019s export compliance department\
\ anonymously or via an organization\u2019s compliance hotline."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:7
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: Reiterate that reporting known or suspected ITAR violations in
good faith will not adversely affect employees.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:8
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: Reiterate that reporting known or suspected export violations will
be used to measure job performance.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:9
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1
description: Include the name and contact information of the personnel responsible
for responding to ITAR compliance inquiries.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1
ref_id: ELEMENT 1C
name: Organizing the Compliance Function Appropriately
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c
description: "Management is responsible for deciding where to locate compliance\
\ personnel within an organization\u2019s structure. This includes establishing\
\ organizational charts and developing descriptions of the organization\u2019\
s trade and export compliance functions and determining the extent to which\
\ the ICP is centralized. The organizational structure should clearly identify\
\ the following areas of authority:"
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
description: Who in management is responsible for overseeing the ICP?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:2
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
description: Who within the ICP is the point of contact regarding export compliance
questions?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:3
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
description: Who within the ICP and/or business functions is responsible for
investigating and identifying the root causes of ITAR violations?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:4
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
description: Who within the ICP and/or business functions is responsible for
overseeing and implementing corrective actions?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:5
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
description: Who within the ICP is responsible for drafting, finalizing, and
submitting export-related documents to DDTC?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:6
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
description: Who within the ICP is responsible for sending other communications
regarding export compliance matters to DDTC, if necessary?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:7
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1
description: Who is responsible for legal interpretation and guidance on internal
export compliance matters?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c
description: "Empowered Officials (EOs) typically handle at least some of the\
\ responsibilities listed above. As set forth in ITAR \xA7 120.67, some of\
\ the primary attributes and responsibilities of an EO include, but are not\
\ limited to:"
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2
description: Direct employment by an organization in a position having authority
for policy or management within the organization
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:2
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2
description: Written legal empowerment to sign license applications and other
requests for approval on behalf of the organization.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:3
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2
description: Understanding the provisions and requirements of the various export
control statutes and regulations and the criminal liability, civil liability,
and administrative penalties for violating the AECA and the ITAR.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2
description: 'Independent authority to:'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4
description: Inquire into any aspect of a proposed export, temporary import,
or brokering activity by the organization;
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4
description: Verify the legality of the transaction and the accuracy of the
information to be submitted to DDTC; and
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4:3
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4
description: Refuse to sign any license application or other request for approval
without prejudice or adverse recourse.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:3
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c
description: Management is responsible through training and hiring practices
for ensuring that compliance personnel possess the requisite technical knowledge,
expertise, and experience to effectively implement the ICP. Management should
also ensure that compliance personnel, including the EO, are delegated sufficient
authority and autonomy to implement the ICP, consistent with their responsibilities.
Management should hold routine and periodic meetings with the EO to ensure
that employees are following ITAR policies and procedures.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2
assessable: false
depth: 1
ref_id: ELEMENT 2
name: DDTC REGISTRATION, JURISDICTION & CLASSIFICATION, AUTHORIZATIONS, & OTHER
ITAR ACTIVITIES
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2
ref_id: ELEMENT 2A
name: Registration
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:1
assessable: true
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a
description: The ICP should include information on registration requirements
in the ITAR.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a
name: Who Needs to Register?
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2
description: "The organization\u2019s ICP should explain who is required to\
\ register with DDTC. The ITAR sets forth the general requirements to register\
\ for manufacturers, exporters, and temporary importers in ITAR part 122 and\
\ for brokers in ITAR part 129, while also imposing registration requirements\
\ in certain unique circumstances. See, e.g., ITAR \xA7\xA7 126.16(k) and\
\ 126.17(k) regarding requirements for intermediate consignees under the Australia\
\ and UK treaties, respectively."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:2
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2
description: The ITAR requires that, subject to certain exemptions, any person
who engages in the United States in the business of manufacturing or exporting
or temporarily importing defense articles, including technical data, or furnishing
defense services, must register with DDTC. Manufacturers who do not engage
in exporting must nevertheless register.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:3
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2
description: The ITAR also requires that, subject to certain exemptions, persons
engaged in brokering activities with respect to the manufacture, export, import,
or transfer of any foreign defense article or defense service must register
with DDTC. The brokering registration requirement applies to any U.S. person,
any foreign person located in the United States, and any foreign person located
outside of the United States and owned or controlled by a U.S. person. A manufacturing
registration does not satisfy brokering registration requirements and vice
versa, and persons engaged in both manufacturing and brokering activities
must register as both a manufacturer and broker.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:4
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2
description: The purpose of registration is primarily to provide the U.S. Government
with visibility into who is involved in ITAR-controlled activities. Registration
does not confer any export, temporary import, or brokering rights or privileges.
Registration also does not constitute a certification of ITAR compliance or
indicate the effectiveness of an ICP.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:5
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2
description: "Registration is generally a precondition to the issuance of any\
\ license or other approval, including the use of certain license exemptions.\
\ Additional DDTC registration information and FAQs can be found on DDTC\u2019\
s website."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:3
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a
name: Types of Registration
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:3:1
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:3
description: 'There are three types of registration: manufacturer, exporter,
and broker. Organizations can apply as a manufacturer, exporter, and/or broker
in one registration application. They will receive a code that corresponds
with their registration type and a completion letter from the DDTC under their
account after payment (currently via Defense Export Control and Compliance
System (DECCS)).'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:4
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a
name: Submitting Registration Applications and Renewals
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:4:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:4
description: "A prospective registrant must electronically submit a Statement\
\ of Registration (Department of State form DS-2032) to the Office of Defense\
\ Trade Controls Compliance (DTCC) by following the submission guidelines\
\ available on the DDTC website and referring to the requirements set forth\
\ in ITAR \xA7 122.2. Registrations are valid for 12 months and must be renewed\
\ annually. The expiration date is included in the registration letter issued\
\ by DDTC. Registration renewal submissions should be submitted through DECCS\
\ up to a maximum of 60 days but no less than 30 days in advance of the renewal\
\ expiration."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a
name: Registration Changes and Notifications
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5
description: 'Registrants are required to notify DDTC within a specified time
period, e.g., five or 60 days, when certain changes in their organization
occur. Changes that require notification to DDTC include, but are not limited
to, when:'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1
description: Certain persons related to the organization have been indicted
or otherwise charged with or convicted of violating certain criminal statutes.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1
description: Organizations change certain information in the Statement of Registration,
such as name, address, ownership, or persons listed on registration.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:3
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1
description: Organizations intend to sell or transfer ownership or control to
a foreign person.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:4
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1
description: Organizations are part of acquisitions or mergers.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:2
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5
description: "Additional notification requirements are found in ITAR \xA7 122.4."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a
name: DDTC Registration Suggestions
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6
description: "Organizations often submit voluntarily disclosures pursuant to\
\ ITAR \xA7 127.12 regarding their failure to notify DDTC of registration\
\ changes required under the ITAR. To reduce the risk of these types of ITAR\
\ violations from occurring, DDTC recommends that organizations take the following\
\ actions:"
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1
description: Understand which activities require an organization to register
with DDTC and determine whether the organization is required to do so.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1
description: Assign a senior officer to oversee the registration process and
to sign the required notifications.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:3
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1
description: Establish and implement policies and procedures to ensure the complete
and timely submission of registration renewals and required notifications
for material changes. For example, create policies and procedures to ensure
that export compliance personnel are informed in advance of changes in senior
officers and mergers and acquisitions to ensure timely updates to the registration
statement.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:4
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1
description: ' Protect registration codes, which are specific to the registrant
and should not be made available publicly.'
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2
ref_id: ELEMENT 2B
name: Jurisdiction and Classification
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:1
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b
description: To determine whether organizations or individuals need to register
or obtain a DDTC license or other approval, they must determine the appropriate
jurisdiction and classification of the commodities they manufacture, export,
temporarily import, or broker. Jurisdiction refers to the set of regulations
to which a commodity is subject, e.g., the ITAR or the Export Administration
Regulations (EAR), whereas classification refers to the specific entry on
the respective control list under which the commodity is described, e.g.,
USML Category VIII(a)(2), or Commerce Control List Export Control Classification
Number ECCN 9A610.a).
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b
name: Commodity Jurisdiction Requests
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2:1
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2
description: "Manufacturers, exporters, and temporary importers may self-classify\
\ their items and services. However, if after reviewing the Order of Review\
\ described in ITAR \xA7 120.11, doubt remains regarding the jurisdiction\
\ and/or classification of an item or service, organizations may submit a\
\ Commodity Jurisdiction (CJ) determination request to DDTC as described in\
\ ITAR \xA7 120.12 for an authoritative determination."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2:2
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2
description: "To submit a CJ request, navigate to DDTC\u2019s website and under\
\ \u201CConduct Business\u201D for instructions on how to submit a Form DS-4076\
\ electronically via DECCS. Please note that a supporting letter from the\
\ original equipment manufacturer (OEM) is generally required for CJ applications\
\ by persons other than the OEM."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b
name: DDTC Jurisdiction and Classification Suggestions
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3
description: 'Organizations routinely disclose to DDTC ITAR violations resulting
from improper jurisdiction and classification. To reduce the risk of these
types of ITAR violations from occurring, DDTC recommends that organizations
take the following actions:'
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: If any doubt exists regarding the proper jurisdiction or classification,
err on the side of caution, and submit a CJ request to DDTC.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: Understand the form and fit of the articles, as well as the function
and performance capability of the articles.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:3
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: Document the design and development process for new products and
monitor and document modifications to existing products.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:4
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: Designate employees with the necessary technical expertise, e.g.,
engineers or program managers, and export controls personnel to perform jurisdiction
and classification review functions.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:5
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: Establish formal written policies and procedures for reviewing
and documenting jurisdiction and classification decisions.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:6
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: "Develop a system of tracking and marking jurisdiction and classification\
\ determinations at the time \u2013 or as soon as possible after \u2013 commodities\
\ are manufactured."
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:7
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: DDTC routinely updates USML categories, so organizations should
consistently monitor these updates and adjust their internal jurisdiction
and classification determinations accordingly.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:8
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: If a CJ request is pending, DDTC recommends treating the commodity
as defense article or a defense service until DDTC issues the CJ determination.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:9
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1
description: Keep records of all jurisdiction and classification decisions in
a central location that can easily be accessed, reviewed, referred to, and
updated.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c
assessable: false
depth: 2
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2
ref_id: ELEMENT 2C
name: Authorizations
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:1
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c
description: "DDTC authorization via a license or other approval is required\
\ prior to engaging in any ITAR-controlled export (see ITAR \xA7 120.50),\
\ reexport (see ITAR \xA7 120.51), retransfer (see ITAR \xA7 120.52), temporary\
\ import (see ITAR 120.53), or brokering activities (see ITAR 129.2(b))."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c
name: Licenses, Agreements, and Other Approvals
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:1
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2
description: "As defined in the ITAR, a \u201Clicense\u201D is a document bearing\
\ the word \u201Clicense\u201D that is issued by DDTC that permits the export,\
\ reexport, retransfer, temporary import, or brokering of a specific defense\
\ article or defense service controlled under the ITAR."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:2
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2
description: "An \u201Cother approval\u201D is a document, other than a license,\
\ issued by DDTC that approves an ITAR-controlled activity or the use of an\
\ exemption to the license requirements in the ITAR. License exemptions are\
\ therefore considered a form of DDTC authorization. Additional information\
\ about obtaining a license or other approval from DDTC can be found on DDTC\u2019\
s website. Licenses are submitted and tracked in DECCS."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2
description: 'Agreements approved by the Office of Defense Trade Controls Licensing
(DTCL) may authorize U.S. persons to furnish defense services and export technical
data to foreign persons, manufacture defense articles abroad, or establish
distribution points abroad for defense articles of U.S. origin for subsequent
distribution to foreign persons or entities. Agreements are submitted and
tracked in DECCS. There are three different types of agreements that cover
these activities:'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3:1
assessable: false
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3
description: 'Manufacturing Licensing Agreements (MLA): agreements whereby a
U.S. person grants a foreign person an authorization to manufacture defense
articles abroad and that involve or contemplate either the export of technical
data or defense articles or the performance of a defense service; or the use
by the foreign person of technical data or defense articles previously exported
by the U.S. person.'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3:2
assessable: false
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3
description: 'Technical Assistance Agreements (TAA): agreements for the performance
of a defense service(s) or the disclosure of technical data, as opposed to
an agreement granting a right or license to manufacture defense articles.'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3:3
assessable: false
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3
description: 'Distribution Agreements: agreements to establish a warehouse or
distribution point abroad for defense articles exported from the United States
for subsequent distribution to entities in an approved sales territory.'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:4
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2
description: "Additional information on agreements can be found on DDTC\u2019\
s website and under ITAR part 124. Guidance for preparing agreements can be\
\ found on DDTC\u2019s website in the Agreement Guidance section, and further\
\ detail is provided in the DDTC\u2019s Guidelines for Preparing Agreements."
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c
name: Reexports, Retransfers, and General Correspondence Requests
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3:1
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3
description: Prior written DDTC approval must be obtained before reselling,
transferring, reexporting, retransferring, transshipping, or disposing of
a defense article to any end user, end use, or destination other than as stated
on the export license or in the Electronic Export Information filing for any
exemption previously claimed. This requirement applies in all circumstances,
except where the transaction is in accordance with the provisions of an exemption
that explicitly authorizes the resale, transfer, reexport, retransfer, or
disposition of a defense article without such approval.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3:2
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3
description: U.S. and foreign persons may submit a written request for approval
of a reexport or retransfer of defense articles or technical data to DTCL
through DECCS. This request is typically referred to as a General Correspondence
(GC) request. Foreign persons may also submit GC requests regarding reexports,
retransfers, or changes in end use to DTCL, and they do not need to be registered
with DDTC in order to do so.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3:3
assessable: false
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3
description: Additional information about approvals for reexports or retransfers
can be found in ITAR part 123.
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c
name: DDTC Licenses, Agreements, and Exemptions Suggestions
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4
description: 'To reduce the risk of ITAR violations related to obtaining and
using licenses, agreements, and exemptions, DDTC recommends that organizations
establish policies and procedures for the following:'
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Incorporating licensing and other authorization considerations
in all appropriate organization processes.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Anticipating, to the extent possible, the need for licenses in
advance of proposed export activities.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:3
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Ensuring that business development, sales, and marketing personnel
understand timelines for obtaining licenses.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:4
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Ensuring ample time to draft, submit, and receive approval for
agreements.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:5
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Ensuring all parties understand appropriate terms, conditions,
and provisos of the agreement, and conducting periodic audits of export activities
under the agreement.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:6
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Performing as much fact finding as practicable ahead of submitting
license applications and anticipating changes that may occur while a license
is valid, e.g., change in freight forwarder, potential U.S. or foreign subcontractors
involved in the transaction, or changes in the end use or end user.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:7
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Reviewing for restrictions on parties to the transaction, including
by screening through the Consolidated Screening List.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:8
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: ' Creating, submitting, tracking and disposition of licenses and
other authorizations.'
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:9
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Successfully implementing agreements (e.g., internal controls,
technology control plans, identifying foreign person status, and employment
status of meeting attendees).
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:10
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Communicating with all foreign parties to determine who will be
involved in the transaction and their roles, e.g., recipients of services,
providers, subcontractors.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:11
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: ' Working with foreign parties to understand if there will be dual
or third- country national employees working on the proposed activities and
how the foreign party will screen those individuals.'
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:12
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Ensuring foreign parties have compliance safeguards in place to
protect any technical data transferred under the agreements from unauthorized
access.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:13
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Protecting against unauthorized release of technical data to foreign
entities and foreign employees.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:14
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Assessing all conditions that must be satisfied to qualify for
use of any license exemption.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:15
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1
description: Reviewing and approving use of license exemptions by appropriate
compliance personnel.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5
assessable: false
depth: 3
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c
name: 'DDTC Reexports, Retransfers, and General Correspondence Requests
Suggestions'
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1
assessable: true
depth: 4
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5
description: 'To reduce the risk of ITAR violations related to the reexport
or retransfer of defense articles from occurring, DDTC recommends that organizations
take the following actions:'
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1:1
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1
description: Establish policies and procedures for reviewing and obtaining authorization
for reexports and retransfers.
implementation_groups:
- DDTC
- urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1:2
assessable: true
depth: 5
parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1
description: Establish policies and procedures for tracking and keeping records
regarding export authorizations for reexports or retransfers.