BAE ITAR Settlement — Part 2: Root Causes and the Real Lessons for Export Compliance

Part 1 of this series walked through the settlement terms and the sheer range of violations DDTC documented against BAE Systems, spanning unlicensed technical data exports, unauthorized defense services, agreement mismanagement, and documentation failures. In Part 2, we focus on what actually caused all of this, because DDTC’s charging letter is unusually candid about root causes, and those root causes are far more instructive than the individual violations themselves.

A People and Process Problem, Not a Willful Evasion Problem

Nothing in DDTC’s findings suggests BAE was trying to evade export controls. Nearly every violation traces back to a breakdown in understanding, process, or system capability rather than intent to circumvent the rules. That distinction matters for how other companies should read this case: BAE is a sophisticated, experienced defense contractor with an established compliance program, and it still accumulated more than 100 violations. If it can happen here, the underlying failure modes are worth taking seriously regardless of how mature a company believes its own program to be.

DDTC’s own summary of root causes reads like a checklist of common compliance program weaknesses: insufficient written procedures, a lack of experience among trade compliance personnel, inadequate management of agreements, and an insufficient IT system for tracking authorizations. BAE told the agency directly that frequent turnover among export compliance employees led to an ineffective transition process for managing its authorizations, that some violations went undetected because of inadequate export management software, and that other violations stemmed from insufficient training. DDTC’s ultimate conclusion was blunt: BAE “lacked a comprehensive compliance program that integrated corrective actions in response to disclosures across the enterprise.”

When Well-Intentioned Employees Still Get It Wrong

Several of the specific fact patterns in the charging letter illustrate exactly how a program can fail even when individual employees are trying to do the right thing. In the China GPS receiver case, BAE’s supply chain team did not fully understand the export control regulations governing the technical data they were handling, and the company’s secure file transfer network did not sufficiently flag export control warnings before files went out the door. There was no formal training and no clear written process telling the supply chain team who to ask when a question came up. That is not an employee ignoring the rules. That is an employee who was never given the tools or the process to recognize the risk in the first place.

The Germany shipbuilding case shows a similar dynamic, but with a near-miss correction built in. A BAE employee sent technical data without first consulting the company’s empowered official, because the document lacked export control markings and didn’t obviously read as controlled. When the German recipient asked for more detail, the same employee recognized the expanded report might be subject to export controls and escalated it, at which point the empowered official determined both documents required a license. The system worked, eventually, but only because an individual employee’s judgment caught what the process itself had missed the first time. That’s a fragile safety net to rely on at scale.

The Switzerland shipping mix-up is perhaps the starkest illustration of a pure process failure. BAE’s export compliance officer had properly reviewed and approved a different, EAR-controlled item for that shipment. The actual failure happened on the loading dock, where employees pulled the wrong part off an export hold shelf and packed it without verifying the part number against the shipping memorandum. No amount of upstream compliance review protects a company from a downstream physical handling error if there’s no verification step built into the shipping process itself.

The Danger of Delegating High-Risk Judgment to Inexperienced Staff

A recurring theme across multiple violation categories is BAE delegating export control judgment calls to junior or inexperienced personnel without adequate guardrails. The company had no formal review process for temporarily imported defense articles awaiting repair, and allowed junior export personnel to process those transactions, which DDTC directly linked to the resulting exemption-usage errors. In the Indonesia case, an export compliance official approved a trip for technical engineers to provide services under a technical assistance agreement that had already terminated, apparently relying on exemptions that authorized technical data transfers but not defense services, a distinction that matters enormously under ITAR but is easy to blur without rigorous review.

This points to a structural lesson: export control judgment calls, particularly ones involving licensing status, exemption applicability, and agreement authorization, need escalation paths to genuinely experienced personnel, not just personnel with a compliance title. A title alone does not substitute for depth of experience with the specific regulatory nuance at issue.

Managing 120-Plus Agreements Without the Right Infrastructure

BAE’s struggles managing more than 120 separate DDTC agreement authorizations point to a scale problem that technology, not just policy, has to solve. Tracking which sublicensees are authorized under which technical assistance agreement, confirming amendments have been executed by every signatory before implementation, and ensuring required forms are collected from foreign parties are all tasks that become unmanageable through manual or fragmented systems once a company’s authorization portfolio grows past a certain size. DDTC’s insistence that BAE implement a comprehensive, automated export compliance system across all its operating divisions, with six-month status reporting, reflects the agency’s own conclusion that this was fundamentally an infrastructure gap as much as a training gap.

Why Earlier Remediation Wasn’t Enough

One of the more sobering details in this case is that BAE had already completed an internal audit back in 2021 that identified areas needing improvement, and the company responded: more experienced personnel in leadership roles, more empowered officials, more compliance training investment, retention incentives, and better IT tools. DDTC acknowledged this produced “some improvement.” But similar violations kept recurring into 2025. The lesson here is important for any company that has already gone through a remediation cycle after an internal audit or disclosure: partial fixes targeting individual symptoms, more training here, an added compliance role there, will not necessarily address a root cause as systemic as BAE’s, which DDTC characterized as a fundamental lack of integration between corrective actions and the enterprise as a whole. Remediation has to close the actual structural gap, not just visibly respond to the most recent finding.

Compliance Takeaways

A few practical lessons stand out for any company operating under ITAR or similar export control regimes.

Export control warnings need to be built into the systems employees actually use, not left to individual awareness. BAE’s file transfer network didn’t adequately flag controlled data before transmission, and that gap, not a lack of good faith, drove real violations.

Turnover in compliance roles is a genuine enterprise risk, not just an HR inconvenience. BAE explicitly linked frequent changes in export compliance personnel to breakdowns in managing its authorization portfolio. Succession planning and documented transition processes for compliance roles deserve the same seriousness as succession planning for any other business-critical function.

Junior personnel should never be the last line of defense on high-risk determinations. Formal review processes and escalation requirements for licensing, exemption, and agreement questions need to route to genuinely experienced staff, not simply whoever is available.

Physical handling and shipping processes need their own verification controls. A compliance program that stops at the point of licensing approval, without a corresponding check at the point of physical shipment, leaves exactly the kind of gap that turned an EAR-controlled shipment into a USML violation in this case.

And finally, remediation after an audit or disclosure needs to address root causes at an enterprise level, not just respond to the specific finding at hand. BAE’s experience shows that incremental improvements, without genuine integration across the compliance program, can still leave a company accumulating new violations years later.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *