Why companies audit
An ITAR compliance audit is usually triggered by growth or change: new defense work, a merger, foreign employees in technical roles, or questions from a customer's compliance team. Prime contractors and government customers increasingly ask suppliers to show how they control defense articles and technical data. An audit also often precedes a decision about whether a past problem should be disclosed to the State Department's Directorate of Defense Trade Controls. Done well, it gives management a realistic view of risk instead of a document that simply says the program exists.
What a review typically covers
Most audits begin with the basics: whether the company is registered with DDTC when it needs to be, and whether its products and technical data have been correctly placed on or off the U.S. Munitions List. From there, reviewers look at how technical data is stored and shared, including cloud storage, email, and access by foreign person employees or contractors. Licenses and technical assistance agreements are compared against what actually happened, because activity outside the scope of an authorization is a frequent problem. Recordkeeping and training round out the picture. Interviews with engineers and shipping staff often reveal more than the written procedures do.
Running the audit under counsel
Where an audit might uncover violations, it is often structured with counsel directing the work, so that findings and advice are protected by privilege to the extent the law allows. That protection depends on how the review is set up and documented, so it should be decided before the work starts. We agree on scope with you, identify who will be interviewed, and set a plan for what happens if a significant issue appears mid-review. Possible outcomes include corrective actions, policy changes, and in some cases a voluntary disclosure, which DDTC takes into account when deciding how to respond. Our report focuses on the issues that matter most and on concrete fixes your team can carry out.