← Compliance as Infrastructure Reference Specification · Concept 04 of 05
Concept 04

Enforcement Gates

Canonical definition

An Enforcement Gate is a system condition placed at a control surface that cannot be bypassed. The system evaluates the object's Control DNA against applicable regulatory conditions and determines whether the transaction proceeds or stops. The evaluation is the proof.

What it is not. An enforcement gate is not an approval step, a sign-off requirement, or a checklist. Those are human interventions, subject to human conditions. A gate holds regardless of who is busy, who is traveling, and what the quarter looks like.

Specification

A control surface is any operational point where regulatory conditions must be evaluated before execution proceeds. Not a compliance task. Not a review activity. A moment where the business and the regulation intersect, where a transaction cannot legally proceed until a compliance condition is satisfied.

Control surfaces are not designed. They are discovered. They exist whether the enterprise recognizes them or not. The enterprise that does not recognize them has unprotected surfaces: points where transactions proceed without the evaluation the regulation requires. Five surfaces are universal to every enterprise that exports controlled technology:

CS1
Technology creation
Classification must be assigned before the product moves.
CS2
Customer qualification
Screening must occur before the relationship advances.
CS3
Order booking
Authorization conditions confirmed before the order is accepted.
CS4
Shipment authorization
License validity confirmed before the shipment releases.
CS5
Payment processing
Authorization confirmed before the payment clears.
Normative rule

A control surface without an enforcement gate is a location where someone should check. An enforcement gate is a system condition that cannot be bypassed. The transaction cannot proceed until the condition is satisfied.

The gate is not a human check. It is a system condition. The shipment cannot release until the license condition is confirmed valid. The condition is either met or it is not. The system evaluates the object's Control DNA against the applicable regulatory conditions and determines whether propagation continues. Deterministic. Not negotiated.

The four design questions

An enforcement gate is designed for each control surface by answering four questions:

Condition
What must be satisfied? The classification assigned and valid. The screening current and clear. The license active and covering this destination, this end user, this quantity, on this date.
Enforcing system
The PLM that cannot release a design without a classification. The CRM that cannot activate a customer without a screening result. The ERP that cannot release a shipment without license validation. The finance system that cannot process a payment without an export authorization flag.
Failure response
What happens when the condition is not satisfied? The transaction pauses and routes to compliance for review, is blocked with an alert, or escalates to the export compliance officer with the specific condition that failed.
Evidence
What record does the gate generate? The condition was evaluated at this timestamp. The result was this. The transaction proceeded or stopped. The responsible actor was this. That evaluation is the proof.

Exceptions are the gate working

Every compliance program generates exceptions: transactions the gate cannot clear automatically because a required condition is unresolved. A false positive screening hit. An emergency shipment before a license renewal completes. A beneficial ownership question opened by an announced acquisition.

These are not failures of the architecture. They are the cases where the architecture correctly stops execution and surfaces the condition for human judgment. The exception workflow has four components: the hold, the review, the authorization, and the record. There is no bypass. There is a resolution path, documented, attributed by name, with a timestamp. The authorization does not override the gate. It satisfies the gate's condition with documented evidence in place of automated clearance.

The exception rate is itself a signal. A rising rate in a specific domain means the gate is encountering conditions the architecture was not designed to handle. Each exception pattern is a design input for the next iteration.

Diagnostic question
Which of our control surfaces have gates, and which have people?

Inventory every point where a compliance evaluation must occur, then ask what enforces it. A required field the workflow cannot skip is a gate. A person who is supposed to check is a surface left unprotected whenever that person is busy, traveling, or under quarter-end pressure.

Experience this concept
Release a shipment and watch the six conditions evaluate →
Normative source
Compliance as Infrastructure, Gloria Gallo, 2026. Part II, The Design Method, step five. Gate architectures for all five domains appear in Part III. A worked gate evaluation in decision logic form appears in Appendix F. This page is the specification. The book is the full treatment.
← Previous concept
The Intelligence Layer