Compliance
as
Infrastructure
An Operating Model for Protecting Revenue, Cash, and Access to Global Markets
Most companies that violate export controls are not unaware of the rules. They have compliance programs. They still fail. The reason is structural.
They had compliance programs.
They did not have compliance infrastructure.
Read through the enforcement record carefully and a pattern emerges. It is not that these companies did not know the rules. Most of them had designated officers. Most of them had policies.
What they did not have was architecture that enforced compliance across the system. Classification data that traveled with the product through every system. Screening that ran on every transaction automatically. Enforcement gates that stopped shipments before authorization.
They had compliance programs. They did not have compliance infrastructure. The real problem is not the violation. It is the design.
The executives who built their mental model before 2022 are running the wrong numbers.
Detection is now continuous and algorithmic. Regulators correlate trade filings, logistics records, financial transactions, and identity data continuously. Risk is detected in motion.
The statute of limitations for most US sanctions violations was extended to ten years. The violations that have not surfaced yet are not forgiven. They are pending.
The maximum administrative penalty per violation is now $374,474, or twice the transaction value — whichever is higher. In 2023, BIS recorded its highest single monetary penalty ever: $300 million. The calculation has changed.
Compliance touches every system. Yet in most organizations it lives nowhere. Pieces of it are scattered across the ERP, the PLM, the CRM, spreadsheets, emails, and the minds of compliance officers. The architecture below gives compliance a place to live. Read the specification →
Regulatory classifications, authorization requirements, jurisdictional conditions, embedded at object formation. Not stored separately. Not consulted after the fact. Traveling with the object.
Governance embedded in execution is not enforcement after the fact. It is the condition under which enforcement is no longer necessary. The architecture either permits the transaction or it does not.
The Compliance Intelligence Function monitors the movement of operational objects across jurisdictional boundaries. Signals emerge from the architecture, not from retrospective review. The enterprise sees compliance status during execution.
At each boundary, the system evaluates the object's Control DNA against applicable regulatory conditions and determines whether propagation can continue. That evaluation is the proof.
Every evaluation leaves evidence. No silent overwrite is allowed. Every structural change creates a new version. Every version preserves prior state. The evidence exists at the moment of decision, not assembled afterward.
Organizations with mature ERP environments embed Control DNA at the transaction level. Organizations earlier in the journey build a Compliance Intelligence Hub that reads existing system outputs and applies governance as an enforcement layer.
Resolved at object formation. Travels without reconstruction at each boundary. The system does not ask whether the transaction is compliant. It reads the object.
Part of the object's structure — not an external checklist applied after the fact. The object either carries the authorization or it does not proceed.
Counterparties, owners, jurisdictions — and which governing conditions those relationships activate. Screened at formation. Not at the point of no return.
Evaluated during execution. Not after. The object carries its jurisdictional profile from the moment it is formed. It does not wait to be evaluated at the dock.
At each stage of its lifecycle. Immutable once set at the relevant control surface. Downstream domains may extend the object. They may not redefine its governing structure.
The system does not ask whether the transaction is compliant. It evaluates the object's attributes against the applicable regulatory conditions and determines whether propagation can continue. That evaluation is the proof.
Export control classification is an R&D decision. The technology being developed determines what can be shipped, to whom, and under what conditions. Organizations that treat compliance as an export function miss where the obligation is created.
Start HereWhat gets built is what gets exported. Component-level control begins here. Engineering decisions about materials and performance thresholds create downstream obligations that architecture must carry forward.
ClassificationThe supply chain is where compliance visibility typically breaks. Third-party suppliers introduce jurisdiction and classification uncertainty. Architecture that cannot see the supply chain cannot evaluate the transaction at the gate.
ScreeningSales moves at commercial speed. Compliance review moves at review cycle speed. The gap between them is where violations occur. Architecture eliminates the gap — the evaluation happens during deal formation.
GatesBy the time a shipment is at the dock, the compliance decision is already made — or should have been. If the object does not carry its compliance status to this point, the human at the dock cannot fix it.
Final GateCompliance
as Infrastructure
An Operating Model for Protecting Revenue, Cash, and Access to Global Markets
The architecture under enforcement conditions. When the framework holds here, the argument is settled.
Get the Book →