BAE Systems $36 Million ITAR Settlement: Part 1 — The Penalty and the Catalog of Violations

The State Department’s Directorate of Defense Trade Controls just handed down a $36 million penalty against BAE Systems, Inc., resolving more than 100 alleged violations of the International Traffic in Arms Regulations and the Arms Export Control Act stretching from 2019 through as recently as March 2025. This is Part 1 of a two-part series on the case. Here, we walk through the settlement structure and the actual catalog of violations, a sprawling list that touches nearly every category of export control failure a defense contractor can commit. Part 2 will dig into the root causes DDTC identified and what other export-controlled companies should take from them.
The Settlement Structure
BAE’s $36 million penalty comes with a meaningful carve-out: $18 million of it is suspended, on the condition that the suspended amount actually gets spent on improving the company’s compliance program. BAE also agreed to a three-year consent agreement requiring a DDTC-approved special compliance officer to monitor and report on the company’s ITAR and AECA compliance. Beyond that, BAE committed to implementing a new automated export compliance system across its operating divisions, conducting a classification review of all hardware, software, and services made or provided by its ITAR-regulated divisions, completing at least one outside compliance audit, and reporting to DDTC on the status of its new compliance system every six months.
DDTC credited BAE for self-disclosing the large majority of the violations, cooperating with the investigation, agreeing to toll the statute of limitations, and making self-initiated improvements to its compliance program along the way, all factors that reduced what could have been a far more severe outcome, including debarment, which DDTC explicitly declined to pursue. But the agency was not shy about noting the limits of that credit: despite earlier corrective action producing “some improvement,” DDTC found that similar violations recurred into 2025, a signal that BAE’s remediation efforts had not yet closed the underlying gaps.
The Violations: A Wide-Ranging Catalog

What makes this case worth studying closely is the sheer range of failure modes documented in DDTC’s 15-page charging letter. This was not one repeated mistake. It was a pattern spanning unlicensed exports, unauthorized retransfers, defense services provided without authorization, agreement mismanagement, and documentation failures, each with its own distinct root cause.
Several of the most serious violations involved unlicensed exports of controlled technical data. In December 2023, BAE exported technical data related to printed wiring boards for GPS receivers to a Chinese manufacturer without a license, conduct DDTC found created potential harm to U.S. national security. A similar category of technical data was sent to Canada in 46 files in 2021, also without a license. BAE separately exported explosive mixture technical data to the U.K. after an employee mistakenly believed the specifications were already in the public domain, and sent Navy guided missile destroyer technical data to a German shipyard after failing to first consult the company’s empowered official because the document lacked export control markings.
Unauthorized defense services made up another significant category. A BAE subcontractor provided defense services in Italy and France on more than 17 occasions, including radar and tracking system testing and maintenance, despite not being listed as an authorized party or registered with DDTC at all. Separately, BAE provided qualification testing services for F-16 support equipment in Indonesia after a prior technical assistance agreement had terminated and before its successor agreement was fully executed, a gap an export compliance official appears to have missed when approving the trip.

Other violations stemmed from processing and shipping errors rather than a failure to understand the rules in the first place. A Switzerland-bound export intended to be an EAR-controlled item was mistakenly swapped on the shipping dock for a USML-controlled engine control unit, because dock employees packed the wrong part without verifying it against shipping documentation. A U.K. project team retransferred F-35-related paint specification data to a manufacturer that had never been added as an authorized sublicensee under the relevant technical assistance agreement, because the team failed to verify recipient authorization before sharing the data.
Layered on top of all of this were systemic agreement-management failures. BAE was managing more than 120 separate DDTC agreement authorizations, and struggled with compliance across that portfolio: violations of technical provisos, premature implementation of technical assistance agreement amendments before all signatories had executed them, missing required foreign-party forms, and breaches of a manufacturing license agreement involving helicopter exports to Japan. The company also failed to timely return temporarily imported defense articles from multiple countries, exceeding the permitted import windows, in part because it had no formal review process for these transactions and delegated them to junior personnel who made repeated exemption-usage errors. Rounding out the list, BAE reported multiple instances of missing or incorrect authorization citations in its export documentation between 2021 and 2025.
Taken together, DDTC counted 25 separate disclosures from BAE, plus one directed disclosure the agency itself initiated after identifying violations BAE had not caught on its own. That is an extraordinary volume of distinct compliance failures for a single enforcement action, and it sets up the real question at the center of this case, which we take up in Part 2: what actually caused a sophisticated, experienced defense contractor to accumulate more than 100 violations across so many different categories, and what does DDTC’s own root-cause analysis tell other export-controlled companies about where their own programs might be exposed.











