Skip to content

Evidence request lists

US ITAR and EAR - Export Control and Data Security

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access Control

USEXPORT-2
Access Controls, Deemed Export, Nationality

Per ITAR/EAR: Access Controls Based on Nationality and Need + deemed export rule + Foreign person access restrictions + Protection of Controlled Unclassified Information.

Artefacts an auditor will ask for
  • ITAR/EAR evidence for USEXPORT-2
Where this commonly fails
  • classification + access + cloud partial

Classification

USEXPORT-1
Jurisdiction and Classification (ITAR USML / EAR CCL)

Per ITAR (22 CFR Parts 120-130) + EAR (15 CFR Parts 730-774): Jurisdiction and Classification of Items + USML vs CCL + Export Control Classification Number (ECCN).

Artefacts an auditor will ask for
  • ITAR/EAR evidence for USEXPORT-1
Where this commonly fails
  • classification + access + cloud partial

Cloud

USEXPORT-3
Cloud and SaaS Use for Controlled Data

Per ITAR/EAR + 2020 ITAR changes: Cloud and SaaS Use for Controlled Data + encryption end-to-end safe harbor + FedRAMP High alignment.

Artefacts an auditor will ask for
  • ITAR/EAR evidence for USEXPORT-3
Where this commonly fails
  • classification + access + cloud partial

Data Security for Controlled Technical Data

US-ITAR-EAR-DS-01
Technical Data Protection

ITAR: protection of defence technical data (Category I-XXI USML). EAR: protection of controlled technology. End-to-end encryption required. Access limited to US persons (ITAR). Deemed export controls for foreign nationals.

Artefacts an auditor will ask for
  • Jurisdiction and classification determinations (CJ/CCATS)
  • Technology Control Plan (TCP) for ITAR/EAR controlled data
  • Cloud and storage controls evidence (encryption and US-person admin)
  • Access control matrix restricting controlled data to authorized U.S. persons
Where this commonly fails
  • Classification of technical data inconsistent across business units
  • Incident response does not address controlled-data spill scenarios
  • Foreign-national access not tracked against deemed-export rules
  • Encryption keys held outside U.S. for ITAR data
US-ITAR-EAR-DS-02
Cloud and Storage

Cloud computing restrictions for ITAR data. End-to-end encryption for cloud storage. US-person-only administrative access. Data centre location considerations. Key management. AWS GovCloud and Azure Government options.

Artefacts an auditor will ask for
  • Access control matrix restricting controlled data to authorized U.S. persons
  • Jurisdiction and classification determinations (CJ/CCATS)
  • Deemed export risk assessment for foreign-national access
  • Cloud and storage controls evidence (encryption and US-person admin)
Where this commonly fails
  • Cloud configurations allow non-US admin access to controlled data
  • Foreign-national access not tracked against deemed-export rules
  • Incident response does not address controlled-data spill scenarios
  • Classification of technical data inconsistent across business units
US-ITAR-EAR-DS-03
Access Controls

US person verification for ITAR access. Need-to-know basis. Physical and logical access controls. Visitor management. Foreign national access restrictions. Export classification determination.

Artefacts an auditor will ask for
  • Deemed export risk assessment for foreign-national access
  • Access control matrix restricting controlled data to authorized U.S. persons
  • Jurisdiction and classification determinations (CJ/CCATS)
  • Technology Control Plan (TCP) for ITAR/EAR controlled data
Where this commonly fails
  • Incident response does not address controlled-data spill scenarios
  • Classification of technical data inconsistent across business units
  • Encryption keys held outside U.S. for ITAR data
  • Foreign-national access not tracked against deemed-export rules

Enforcement

USEXPORT-5
Voluntary Disclosure, Enforcement, Penalties

Per ITAR/EAR + DDTC + BIS: voluntary disclosure + enforcement + civil + criminal penalties + denied parties screening.

Artefacts an auditor will ask for
  • ITAR/EAR evidence for USEXPORT-5
Where this commonly fails
  • classification + access + cloud partial

ITAR and EAR: Deemed Export and Access Management

ITAR-EAR-DeemedExport
Deemed Export Controls

Releases of controlled technology or source code to foreign persons inside the United States are deemed exports to the foreign person's country of most recent permanent residency or citizenship and require the same authorizations as a physical export.

Artefacts an auditor will ask for
  • Foreign person screening records during hiring and onboarding
  • Technology Control Plan
  • Deemed export licenses where required
  • Access logs showing nationality based restrictions enforced
Where this commonly fails
  • No country of citizenship screening for visiting researchers or contractors
  • Technology Control Plan absent
  • Cloud collaboration tools allow access by foreign nationals without authorization
ITAR-EAR-Visitor
Visitor and Foreign National Access Management

Manage physical and logical access for visitors, contractors, and foreign nationals to facilities and systems containing controlled technical data through pre approval, escort, badging, briefings, and Technology Control Plan compliance.

Artefacts an auditor will ask for
  • Visitor pre approval workflow
  • Foreign national visit request records
  • Escort assignments
  • Badge access logs for controlled areas
Where this commonly fails
  • Foreign visitors permitted without pre approval
  • No briefing on prohibited topics
  • Badge logs unreviewed

ITAR and EAR: Registration and Classification

ITAR-EAR-FundamentalResearch
Fundamental Research and Public Domain

Document determinations that information qualifies as fundamental research, publicly available information, or educational information exempt from ITAR or EAR controls, and ensure research agreements do not impose publication restrictions that would defeat the exemption.

Artefacts an auditor will ask for
  • Research agreement review procedures
  • Publication restriction flagging
  • Fundamental research determinations by research office
  • Training for principal investigators
Where this commonly fails
  • Research agreements contain publication delays beyond patent review without flagging
  • No determinations documented for grey area projects
  • PIs unaware of export controls in joint research
ITAR-EAR-Registration
DDTC Registration and BIS Awareness

Manufacturers, exporters, and brokers of defense articles or services on the US Munitions List must register with the Directorate of Defense Trade Controls. Exporters of items on the Commerce Control List must be aware of and comply with the Export Administration Regulations administered by the Bureau of Industry and Security.

Artefacts an auditor will ask for
  • DDTC registration letter (DS 2032 evidence)
  • Annual renewal records
  • Designated Empowered Official appointment
  • BIS contact and account records where applicable
Where this commonly fails
  • Lapsed DDTC registration
  • No Empowered Official appointed in writing
  • Subsidiaries not registered separately

ITAR and EAR: Screening and End Use Diligence

ITAR-EAR-EndUse
End Use and End User Diligence

Establish know your customer procedures and resolve red flags before proceeding with transactions. Special diligence applies to military, military intelligence, and security end users in countries identified in 15 CFR 744, and to chemical, biological, nuclear, and missile end uses.

Artefacts an auditor will ask for
  • End user statements (DSP 83 where required)
  • Red flag resolution memos
  • Military End User and Military End Use determinations
  • Diligence questionnaires
Where this commonly fails
  • No red flag indicator list applied to orders
  • DSP 83 missing for Significant Military Equipment
  • Reliance on freight forwarder assurances without verification
ITAR-EAR-RestrictedParty
Restricted Party Screening

Screen customers, partners, suppliers, freight forwarders, and end users against US government denied, debarred, and blocked party lists prior to export, re export, or in country transfer, and rescreen periodically and upon material change.

Artefacts an auditor will ask for
  • Screening tool configuration covering DDTC Debarred, BIS Entity List, OFAC SDN, DPL, Unverified List, Military End User List
  • Screening logs for transactions
  • Periodic rescreening evidence
  • Match resolution records
Where this commonly fails
  • Screening occurs only at onboarding
  • Lists not refreshed daily
  • Match resolutions not documented

ITAR and EAR: Shipping, Recordkeeping and Corporate Change

ITAR-EAR-MA
Mergers, Acquisitions, and Divestitures

Notify DDTC of material changes including mergers, acquisitions, divestitures, changes of senior officers, address changes, and foreign ownership changes within prescribed timelines, and assess CFIUS implications for transactions involving foreign acquirers.

Artefacts an auditor will ask for
  • Material change notification letters to DDTC
  • CFIUS filings where applicable
  • Updated DS 2032
  • Foreign ownership control and influence (FOCI) mitigation if required
Where this commonly fails
  • DDTC not notified within 60 days of material change
  • Foreign ownership changes unreported
  • No FOCI mitigation plan despite foreign investment
ITAR-EAR-Recordkeeping
Recordkeeping

Maintain records of all export transactions, license applications, classification determinations, restricted party screening, end user statements, and shipping documents for at least five years from the date of the export or expiration of the license, whichever is later.

Artefacts an auditor will ask for
  • Document retention policy citing five year minimum
  • Sample transaction file showing all required documents
  • Archive storage with integrity controls
  • Access controls on records
Where this commonly fails
  • Records dispersed across business units without central index
  • Less than five year retention in shipping system
  • Classification records destroyed with product
ITAR-EAR-Shipping
Physical Export Controls and Shipping

Ensure controlled shipments are accompanied by accurate Electronic Export Information filings, license citations or exception symbols, destination control statements, and tamper evident packaging, and that freight forwarders are vetted and instructed.

Artefacts an auditor will ask for
  • AES filings
  • Commercial invoices with destination control statement
  • Freight forwarder agreements and instructions
  • Shipping checklist for controlled items
Where this commonly fails
  • AES filings missing license citation
  • Destination control statement absent
  • Freight forwarder not vetted against denied parties

ITAR and EAR: Technical Data Protection

ITAR-EAR-Encryption
Encryption of Technical Data and Technology

Use end to end encryption meeting FIPS 140 validated cryptographic modules or equivalent National Security Agency approved algorithms when storing or transmitting unclassified technical data across networks, with cryptographic keys retained under US persons control to qualify for the ITAR encryption carve out.

Artefacts an auditor will ask for
  • FIPS 140 validation certificate of modules in use
  • Key management policy showing US person control
  • Encryption configuration for cloud storage and email
  • Documented compliance with 22 CFR 120.54
Where this commonly fails
  • Cloud provider holds keys rather than the exporter
  • TLS only protection without at rest encryption
  • Use of non FIPS validated modules
ITAR-EAR-ITSecurity
IT Security Controls Supporting Export Compliance

Implement information security controls that enforce export compliance, including data loss prevention rules tuned to controlled categories, segmentation of controlled environments, monitoring of cross border data transfers, and incident response procedures for suspected unauthorized releases.

Artefacts an auditor will ask for
  • DLP policy rules for controlled keywords and file fingerprints
  • Network segmentation diagrams for ITAR enclaves
  • Egress monitoring logs
  • Incident response runbooks for suspected unauthorized export
Where this commonly fails
  • DLP not tuned to detect controlled markings
  • Flat networks with controlled and uncontrolled data mixed
  • No alerts for international file transfers

ITAR and EAR: Training

ITAR-EAR-Training
Export Compliance Training

Provide initial and recurring export compliance training to personnel involved in research, engineering, manufacturing, sales, supply chain, IT, and human resources, with role specific modules for deemed export risks and red flag recognition.

Artefacts an auditor will ask for
  • Annual training records by role
  • Course content covering ITAR, EAR, OFAC, deemed exports, red flags
  • New hire training completion
  • Refresher training upon regulatory change
Where this commonly fails
  • Training generic and not role specific
  • No training for HR on deemed export hiring obligations
  • Completion below 95 percent

Licensing

USEXPORT-4
Licensing, Recordkeeping, Self-Assessment

Per ITAR/EAR: licensing + recordkeeping (10 years for EAR + 5 for ITAR) + Internal Audit and Self Assessment + voluntary disclosure.

Artefacts an auditor will ask for
  • ITAR/EAR evidence for USEXPORT-4
Where this commonly fails
  • classification + access + cloud partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US ITAR and EAR - Export Control and Data Security framework page.