← Compliance as Infrastructure Reference Specification · Concept 01 of 05
Concept 01

Control DNA

Canonical definition

Control DNA is the structured regulatory identity of a controlled item or transaction: the complete set of regulatory attributes, embedded at object formation, that travels with the object through every system that touches it.

What it is not. Control DNA is not a classification code, a compliance database, or documentation held by the compliance department. A classification that lives outside the operational systems is knowledge. Control DNA is structure.

Specification

Before a product can be governed it must be understood. Before a transaction can be evaluated it must carry the regulatory meaning that makes evaluation possible. Before any system in the enterprise can enforce a compliance condition, it must know what it is enforcing. Control DNA is where that knowing lives.

It is not a classification code. The classification code is one element of it. Control DNA is the complete set of regulatory attributes that must travel with a product or transaction through every system that touches it. For a controlled technology it includes, at minimum:

Classification
The ECCN or USML designation that determines the regulatory framework governing the item.
Jurisdiction
Whether the item is governed by EAR, ITAR, or both. Dual-use items, 600 series ECCNs, and items subject to Export Control Reform require careful analysis. Getting jurisdiction wrong is one of the most common and most consequential classification errors.
Reason for control
Why the item is controlled. National security. Missile technology. Chemical and biological weapons. Nuclear nonproliferation. The reason for control determines which license exceptions are available and which destinations and end users are prohibited.
Authorization conditions
What is required to export the item. No License Required. A specific license exception. A license application. The conditions that must be satisfied before the item moves.
Identity relationships
Which customers, suppliers, and transactions are authorized under which conditions. Who has been screened, when, against which lists, with what result.

The same principle extends beyond export classification. Screening results, license conditions, authorization states, and ownership and beneficial interest under the BIS 50 percent rule are each threads in the Control DNA. Together they form the complete regulatory identity of every controlled object moving through the enterprise.

Propagation

Control DNA does not remain where it is created. Classification assigned in engineering means nothing if it stays in engineering. The product master in the ERP needs to know it. The customer record in the CRM needs to reference it. The shipment instruction needs to carry it. The export filing needs to reflect it.

Propagation does not mean every system stores the classification independently. It means every system references one authoritative record and inherits its meaning automatically. When the classification changes in the product master, every system that references it sees the change simultaneously, without anyone having to notify anyone.

When each system maintains its own version of the product's regulatory identity, the systems diverge. The ERP has one classification. The CRM has another. The compliance team has the correct one in a spreadsheet that nobody else accesses. The enterprise is running multiple versions of regulatory reality simultaneously.

Normative rule

When Control DNA exists as structured data inside operational systems, it propagates automatically. When it exists in a spreadsheet or a policy document, it does not propagate at all.

Conformance requirements

The most common classification failure is not a wrong answer. It is no answer. Classifications assigned years ago and never reviewed. Products that changed while their classification did not. The gap builds silently until a transaction surfaces it. Preventing it requires three conditions:

R1
Assigned at creation
Not retrospectively. Not periodically. Not when someone remembers to ask. A required field that cannot be left empty.
R2
Reviewed on change
Automatically triggered by engineering change orders, component substitutions, and performance modifications.
R3
Updated on list change
Regulatory lists monitored continuously, so a CCL amendment or USML revision triggers immediate review of affected items.

None of this requires sophisticated technology. It requires discipline embedded in workflow. Simple architecture, consistent execution, and the gap does not form.

Diagnostic question
Where does Control DNA live in our enterprise right now?

Not where it should live. Where it actually lives. Is the export classification in the product master, or in a spreadsheet? Is the screening result in the customer record, or in a compliance database the CRM never references? The answer to that question is a map of the gaps.

Experience this concept
Create a product and watch Control DNA attach at the creation gate →
Normative source
Compliance as Infrastructure, Gloria Gallo, 2026. Part II, Control DNA. A complete worked Control DNA record, field by field, appears in Appendix F. This page is the specification. The book is the full treatment.
← Specification
All concepts