Control DNA is the structured regulatory identity of a controlled item or transaction: the complete set of regulatory attributes, embedded at object formation, that travels with the object through every system that touches it.
Before a product can be governed it must be understood. Before a transaction can be evaluated it must carry the regulatory meaning that makes evaluation possible. Before any system in the enterprise can enforce a compliance condition, it must know what it is enforcing. Control DNA is where that knowing lives.
It is not a classification code. The classification code is one element of it. Control DNA is the complete set of regulatory attributes that must travel with a product or transaction through every system that touches it. For a controlled technology it includes, at minimum:
The same principle extends beyond export classification. Screening results, license conditions, authorization states, and ownership and beneficial interest under the BIS 50 percent rule are each threads in the Control DNA. Together they form the complete regulatory identity of every controlled object moving through the enterprise.
Control DNA does not remain where it is created. Classification assigned in engineering means nothing if it stays in engineering. The product master in the ERP needs to know it. The customer record in the CRM needs to reference it. The shipment instruction needs to carry it. The export filing needs to reflect it.
Propagation does not mean every system stores the classification independently. It means every system references one authoritative record and inherits its meaning automatically. When the classification changes in the product master, every system that references it sees the change simultaneously, without anyone having to notify anyone.
When each system maintains its own version of the product's regulatory identity, the systems diverge. The ERP has one classification. The CRM has another. The compliance team has the correct one in a spreadsheet that nobody else accesses. The enterprise is running multiple versions of regulatory reality simultaneously.
When Control DNA exists as structured data inside operational systems, it propagates automatically. When it exists in a spreadsheet or a policy document, it does not propagate at all.
The most common classification failure is not a wrong answer. It is no answer. Classifications assigned years ago and never reviewed. Products that changed while their classification did not. The gap builds silently until a transaction surfaces it. Preventing it requires three conditions:
None of this requires sophisticated technology. It requires discipline embedded in workflow. Simple architecture, consistent execution, and the gap does not form.
Not where it should live. Where it actually lives. Is the export classification in the product master, or in a spreadsheet? Is the screening result in the customer record, or in a compliance database the CRM never references? The answer to that question is a map of the gaps.