When defence technology companies are asked about their key legal risks, the answers usually revolve around investment, intellectual property or public procurement. Export controls are mentioned far less often. Yet this may be precisely where some of the most significant risks lie, with potentially serious consequences for both a company’s finances and its growth plans, writes Artur Sanglepp, an attorney-at-law at RASK specialising in defence law, who recently spoke on the same topic at the DefenceTech Meetup
In August this year, BAE Systems’ US subsidiary, BAE Systems, Inc., reached a settlement with the US Department of State resolving 104 alleged export control violations. Under the settlement, the company agreed to pay a USD 36 million civil penalty. What makes the case particularly noteworthy is that half of the penalty was suspended on the condition that the company invest the same amount in strengthening its export control compliance programme. In effect, the regulator required the company to spend USD 18 million on measures that could have been implemented at a significantly lower cost before the problems arose.
In the world of defence and dual-use goods and technologies, export controls tend to be associated primarily with physical products. A common assumption is that if a product does not cross a border, export controls do not apply. In practice, the situation is considerably more complex.
The BAE case illustrates that the issues were not limited to the movement of physical products. The violations included the transfer of technical data to various countries, the sharing of technical specifications, and even the provision of defence services without the required authorisations. This highlights a common misconception: companies generally understand that exporting a weapons system or another controlled product requires careful consideration, but often fail to recognise that the same restrictions may also apply to technical documentation, drawings, source code, training or consultancy services.
This is why every export control analysis begins with three straightforward questions. First, a company needs to understand what it is actually selling. Is it a product, a service, or a combination of the two? Second, it needs to determine whether that product or service is subject to export controls at all. Third, and only then, can it assess which licences and procedures are required to supply it to a customer in another country. Too often, companies start with the final question even though the answers to it depend on the first two.
One of the most important practical issues is classification. In the European Union, companies generally need to determine whether their products, technology or services are subject to controls applicable to military or dual-use items. Incorrect classification can render a company’s entire subsequent compliance programme ineffective. Yet in practice, it is not uncommon to encounter companies that cannot say with certainty which control category their core product falls under. Sooner or later, however, the same question is likely to be raised by an investor, customer or regulator.
Companies also tend to focus solely on what they sell. It is equally important to understand what they buy. Defence technology developers increasingly rely on advanced components that may themselves be subject to export restrictions. Investors are increasingly asking whether companies understand the origin and regulatory status of their critical components. If a company cannot answer that question, it may find itself in a difficult position precisely when seeking to raise capital or secure a strategic partner.
In practice, some of the most significant risks arise from technology transfers. The regulatory framework governing military goods takes a broad approach to what constitutes technology. If information is required for the development, production, use, maintenance or repair of a controlled product, sharing that information across borders may itself be subject to export controls.
In today’s international business environment, this means that the risk may not arise when a container leaves a port, but rather when an engineer shares technical documentation with a foreign partner or uploads data to a cloud environment that can be accessed from another country.
Effective export control compliance therefore involves much more than applying for licences. Internal awareness is equally important. Employees need to understand what information is controlled, when the person responsible for export control compliance should be involved, and how risks should be assessed. In practice, systematic training, clear procedures and technical safeguards are among the most effective ways of preventing inadvertent violations.
Investors and potential acquirers are also increasingly asking whether a company has an Internal Compliance Programme (ICP) for export controls. Such a programme sets out responsibilities, classification procedures, licence management, internal audits, training requirements and document retention policies. There is no one-size-fits-all solution. An effective programme must reflect the company’s specific business model, technology and target markets.
The main lesson from the BAE case, however, is not the size of the penalty. More importantly, establishing robust export control processes before problems arise is far less costly than addressing deficiencies afterwards. In addition to potential penalties, inadequate processes may result in shipments being held up, delayed transactions, difficult negotiations with investors or obstacles to raising capital.
For a defence technology company, a well-designed compliance system can strengthen investor confidence, reduce business risks and open doors to international markets. In other words, export control compliance is not merely a safeguard against potential violations – it can also provide a significant competitive advantage for companies seeking to scale rapidly.
In August this year, BAE Systems’ US subsidiary, BAE Systems, Inc., reached a settlement with the US Department of State resolving 104 alleged export control violations. Under the settlement, the company agreed to pay a USD 36 million civil penalty. What makes the case particularly noteworthy is that half of the penalty was suspended on the condition that the company invest the same amount in strengthening its export control compliance programme. In effect, the regulator required the company to spend USD 18 million on measures that could have been implemented at a significantly lower cost before the problems arose.
In the world of defence and dual-use goods and technologies, export controls tend to be associated primarily with physical products. A common assumption is that if a product does not cross a border, export controls do not apply. In practice, the situation is considerably more complex.
The BAE case illustrates that the issues were not limited to the movement of physical products. The violations included the transfer of technical data to various countries, the sharing of technical specifications, and even the provision of defence services without the required authorisations. This highlights a common misconception: companies generally understand that exporting a weapons system or another controlled product requires careful consideration, but often fail to recognise that the same restrictions may also apply to technical documentation, drawings, source code, training or consultancy services.
Three key questions in export control compliance
This is why every export control analysis begins with three straightforward questions. First, a company needs to understand what it is actually selling. Is it a product, a service, or a combination of the two? Second, it needs to determine whether that product or service is subject to export controls at all. Third, and only then, can it assess which licences and procedures are required to supply it to a customer in another country. Too often, companies start with the final question even though the answers to it depend on the first two.
One of the most important practical issues is classification. In the European Union, companies generally need to determine whether their products, technology or services are subject to controls applicable to military or dual-use items. Incorrect classification can render a company’s entire subsequent compliance programme ineffective. Yet in practice, it is not uncommon to encounter companies that cannot say with certainty which control category their core product falls under. Sooner or later, however, the same question is likely to be raised by an investor, customer or regulator.
Companies also tend to focus solely on what they sell. It is equally important to understand what they buy. Defence technology developers increasingly rely on advanced components that may themselves be subject to export restrictions. Investors are increasingly asking whether companies understand the origin and regulatory status of their critical components. If a company cannot answer that question, it may find itself in a difficult position precisely when seeking to raise capital or secure a strategic partner.
The greatest risk may be in a file, not a shipment
In practice, some of the most significant risks arise from technology transfers. The regulatory framework governing military goods takes a broad approach to what constitutes technology. If information is required for the development, production, use, maintenance or repair of a controlled product, sharing that information across borders may itself be subject to export controls.
In today’s international business environment, this means that the risk may not arise when a container leaves a port, but rather when an engineer shares technical documentation with a foreign partner or uploads data to a cloud environment that can be accessed from another country.
Effective export control compliance therefore involves much more than applying for licences. Internal awareness is equally important. Employees need to understand what information is controlled, when the person responsible for export control compliance should be involved, and how risks should be assessed. In practice, systematic training, clear procedures and technical safeguards are among the most effective ways of preventing inadvertent violations.
Investors and potential acquirers are also increasingly asking whether a company has an Internal Compliance Programme (ICP) for export controls. Such a programme sets out responsibilities, classification procedures, licence management, internal audits, training requirements and document retention policies. There is no one-size-fits-all solution. An effective programme must reflect the company’s specific business model, technology and target markets.
The main lesson from the BAE case, however, is not the size of the penalty. More importantly, establishing robust export control processes before problems arise is far less costly than addressing deficiencies afterwards. In addition to potential penalties, inadequate processes may result in shipments being held up, delayed transactions, difficult negotiations with investors or obstacles to raising capital.
For a defence technology company, a well-designed compliance system can strengthen investor confidence, reduce business risks and open doors to international markets. In other words, export control compliance is not merely a safeguard against potential violations – it can also provide a significant competitive advantage for companies seeking to scale rapidly.