Load Factor

The standard

Export control and ITAR screening in aerospace and defense marketing: the procedure that runs before anything sends or publishes

The sentence you are looking for is this one

We do not make export determinations.

We run a screen, we log the result, and we route anything ambiguous to the party entitled to decide it: your own empowered official or export compliance officer. Nothing on this page is legal advice.


Why a publisher has this page

We are a publisher for aerospace and defense. We sell companies a channel on our titles for their own announcements and their people's pieces, labelled as theirs. In this industry, that has an export-control side: releasing controlled technical data to a foreign person is treated as an export to that person's country, whether it happens by email or on a public page.

So everything we publish passes a content screen first, and every piece we produce for a company's channel goes to that company for written approval before it runs. Where a company hires us to write to the people it sells to, which we do only as custom work quoted in writing, every message passes the full six-step procedure below. This page is that procedure, written out in the form it runs, so your compliance officer can read it and audit it.


Two design principles, before the steps

The screen over-blocks on purpose. A wrongly blocked message costs a person two minutes. A message that should have been blocked costs you a disclosure. Those two errors are not the same size, so every threshold below is set to make the first error and never the second.

The strongest control is not the screen. It is the source rule. Every fact in a message must come from a public source with a URL behind it. If nothing in a message came out of your documents, the technical-data question has largely answered itself before the screen runs. The screen then confirms the rule was followed. The source rule is step five of the procedure below.

One consequence: we send few messages. A person reads every message before it goes, and the full screen runs on every one.


The procedure

Six steps, in the order they run.

1. Restricted-party screening

Every recipient is screened against the Consolidated Screening List and the OFAC Specially Designated Nationals files before a message can enter a send queue.

Four strings are screened, plus the parent: the individual's name, the company's legal name, the company's common name, and the registered organisation behind the email domain where that resolves, together with the known parent or ultimate owner of the company.

Fuzzy matching is used, with the threshold set deliberately loose. A near-match counts as a hit for this step.

Any hit or near-hit is a hard block. The message does not enter the send queue under any circumstance, and no score overrides that. It goes to the escalation record with the list it matched, the entry it matched and the match score.

The screening-list version and its retrieval date are recorded against every message, so a verdict can be reproduced later against the lists as they stood on the day. The list files are refreshed quarterly and on demand. If a refresh fails, the run does not proceed. There is no degraded mode for restricted-party screening.

2. Jurisdiction and person flags

Recorded for every recipient: country of location, the company's country of incorporation where it is known, and whether the recipient is understood to be a US person or a foreign person, with the basis for that belief written down.

Recorded once per sequence, from what you state before it starts: whether the subject matter of the outreach is understood to be controlled under the ITAR munitions list or the EAR. If you have not stated it, that is itself an escalation, and the sequence does not start.

Steps 3 and 4 are designed to keep controlled technical data out of the message in the first place, so the jurisdiction flag is a second check behind them. It exists so that a borderline content result and a foreign recipient escalate together, instead of each passing on the strength of being individually borderline.

3. Content classification, layer A: the term screen

Every drafted message is run against a maintained list of controlled terms. The list is versioned, and the version is recorded against the message.

The list is maintained in six categories:

  • USML category terms and named defense programmes.
  • Quantitative performance characteristics attached to a product.
  • Part numbers carrying revision suffixes, drawing numbers, and document control numbers.
  • Control markings and code patterns, including ECCN-shaped tokens and USML category references in Roman-numeral form.
  • Words that indicate technical data as distinct from marketing information.
  • Confidentiality markers.

The terms themselves are not published. What is published is the rule the list implements, further down this page, which is the part you can check the screen against.

Layer A catches the obvious. The judgment happens in layer B.

4. Content classification, layer B: the six questions

Six fixed questions are asked of every message. Each must be answered with either a quoted span from the message or the single word none.

An answer that paraphrases is treated as a failure of the screen, and the message is escalated. A reviewer who cannot quote the span it is worried about has not located it.

The six questions, exactly as the screen asks them:

  1. Does this message state a numeric performance characteristic of any product?
  2. Does this message describe how anything is designed, developed, produced, assembled, operated, repaired, tested, maintained or modified?
  3. Does this message name a defense programme, a contract number, or a controlled activity?
  4. Does this message contain any fact that does not trace to a public URL in its source list?
  5. Does this message reference or paraphrase any client technical documentation?
  6. Would any sentence here be a problem if the recipient forwarded it to a competitor, a journalist, or a regulator?

One quoted span on any of the six sends the message to escalation, not to the send queue. There is no scoring on layer B, and there is no threshold. One span is enough.

The two layers are tuned differently on purpose. When a batch blocks more than a quarter of its messages, we narrow the term list in layer A. We never loosen the six questions. Layer B is the substantive question set, and changing it would change what this procedure claims to do.

5. Source provenance

Every factual assertion in a message maps to a public URL in that message's source list, and every one of those URLs has been checked against the page it points to within the last thirty days.

Your own documents are never a permitted source for outreach copy.

Not your specifications, not your test reports, not your interface control documents, not the deck you sent us, and not a paraphrase of any of them.

6. Human sign-off

The screen produces a batch file: one row per message, with the verdict, the flagged spans if there are any, the source URLs, the recipient's country and the screening-list version.

A named person approves the batch in one recorded action, marking any individual message to be held. The approval, with that person's identity and a timestamp, is written into the audit log.

A message with no logged approval cannot be sent. That is enforced in software: the send job refuses to transmit any message absent from the approval record.

Nothing sends autonomously at any point in this procedure, and no message leaves without a person having read it.


The rule the screen implements

The export regulations' definition of technical data excludes general system descriptions and basic marketing information about a product's function or purpose. That leaves a rule short enough to hold in your head:

A marketing message may say what a product is for. It may not say how it performs, how it is built, or what it was tested to.

The term list and the six questions are an implementation of that rule. When the two disagree, the rule governs and the term list gets amended.

Every definition this procedure depends on is re-pulled and re-checked quarterly, per the record section below.


What happens when something is flagged

For a sequence run for your company, everything in the escalation queue routes to your own empowered official or export compliance officer, and it is resolved there.

The escalation carries the message, the flagged span, and the specific question that flagged it, with a request for a written yes or no. Blocked messages do not send in the meantime, and no deadline releases one.

Ambiguity goes to your empowered official, the answer is logged, and nothing sends until it comes back.

The answer is then logged against both the message and the term list, so the same question is never escalated to you twice. Your first answer on a question is the answer the screen carries from then on.


The record

Every message writes a line to the export screen log, and the log carries the fields an audit would ask for: message id, recipient, company, countries, screen version, term-list version, screening-list version, each layer's verdict, every flagged span, the source URLs behind the message, the approver, the approval timestamp, the send timestamp, and any escalation reference.

The log is yours to read.

Records are retained for five years. That is the recordkeeping period the export regulations impose on registrants.

The definitions are re-pulled quarterly and diffed. Once a quarter, the current text of the technical data, public domain and empowered official definitions is pulled from the eCFR, diffed against the stored copy, and the changes reported. The screening-list files are refreshed in the same job and the endpoints re-verified. This step keeps the procedure aligned with the regulations as they stand.

The screen is audited against itself. Each month, a ten percent sample of sent messages is re-screened cold, and any disagreement with the original verdict is reviewed by a person. The question that sample answers is whether the screen has drifted. A screen that blocks nothing for four consecutive weeks is reported as suspicious, and a deliberately failing test set is run against it to confirm it still catches what it is built to catch.


The same rule covers what we publish

The six steps above run on outreach. The content rule behind them, the term screen and the six questions run on everything we publish: the record, the stories, and every piece produced for a company's channel on our titles.

For a produced piece, the control is the company's own approval. The piece is drafted from an interview with a named person at the company and from public sources. It passes the content screen before the company sees it, and it may contain no technical data beyond what the company has already published on its own website. Nothing runs until the company has approved it in writing. That approval is the company's decision that the piece is cleared for public release, made under its own process; the approval is logged. An announcement we reproduce on a channel comes to us only as a link to something the company has already published, so the company's own review has already decided it.


The limits, stated by us

We are not a licensed customs broker, an export attorney, or an empowered official, and we do not act as one. The contract places export-control determinations with your own empowered official and describes our role as screening and escalation, which is what this page says, written where it is enforceable.

This screen reduces the chance that a marketing message contains controlled technical data. It does not make you compliant. What is on offer here is that one specific activity, run by one specific vendor, is logged to a standard your own function can audit.

Whether your subject matter is controlled is stated by you before a sequence starts, and we take that statement as given. Where you have not stated it, nothing starts.


Then somebody in your commercial organisation is considering a channel on our titles, or outreach run by us, and wants to know whether it is a problem before spending your time on it.

This page is the procedure in full, in the form your review would ask for it. If your review needs something that is not here, ask for it, and we will publish it or tell you why we will not. If your company goes ahead, this page is the appendix to the proposal.

The person who wrote this procedure is Senior Director of Marketing at an aviation software group, with audiences across OEM, MRO, operator and regulator: Reuben Mann.

Send us a link to something your company has published/record/submit

What a channel is, and what it costs → /publish