Contracts Around the World

Contracts Around the World

di Marissa Shaffer
Stagione 1

How Emailed Blueprints Trigger Export Fines

IA
This episode breaks down how everyday procurement actions—such as emailing a CAD drawing or onboarding a non-U.S. worker—can trigger severe U.S. export control violations with multi-million dollar penalties. Operating as expert procurement and contracts guides, the hosts debunk the "shipping box myth" by detailing the mechanics of deemed exports, comparing the zero-tolerance ITAR "see-through" rule against the EAR de minimis threshold, highlighting hidden gaps in HR, IT, and cloud environments, and laying out an actionable 30-60-90 day compliance playbook. Podcast Episode Notes 1. The "Shipping Box Myth" & High-Stakes Penalties The 90-Second Violation Severe Liability Real-World Enforcement Case Studies 2. Deemed Exports & Defining a "Foreign Person" The Clean Room Analogy Legal Definition Everyday Leaks 3. Regulatory Frameworks: ITAR vs. EAR ITAR (State Dept / DDTC) EAR (Commerce Dept / BIS) 4. Order of Review & Evaluation Mechanics Mandatory Order of Review The "Specially Designed" Trap The 4-Question Screen The Encryption Trap 5. Internal Leaks: HR, IT, & Cloud Security Passport Divergence Form I-129 HR Gap The Cloud & FedRAMP Illusion Defense Services Felony 6. Operating Models & Global Supplier Friction 3 Operating Models:Enclave & Data Minimization (Safest) License & Share (Brittle) Design Out (Hardest) The "ITAR Free" Myth GDPR Workarounds Chief Compliance Officer legal attestation and enforcing role-based access controls rather than collecting employee passport copies. 7. Case Studies, Rules, & Emergency Protocols Professor John Reece Roth Case The Affiliates Rule 24-Hour Emergency Protocol: 8. The 30-60-90 Day Action Plan

Auditing Foreign Suppliers Under US Defense Contracts

IA
This episode explores the complex operational and legal challenges U.S. defense contractors face when auditing foreign commercial suppliers. It details how federal regulations reach overseas entities through contractual flow-downs, examines key legal liabilities under the False Claims Act, maps out compliance across five core operational buckets, and presents an 8-step audit playbook to navigate foreign legal hurdles like GDPR, German Works Councils, and European criminal codes. Podcast Episode Notes 1. The Mechanics of Regulatory Flow-Downs The Privity Dilemma Flow-Down Categories The Commercial Item Shortcut (FAR 52.244-6) 2. Legal Enforcement & False Claims Act (FCA) Risks The Danger of Blanket Clauses Key Supreme Court Precedents:Universal Health Services v. U.S. ex rel. Escobar (2016): Established the standards for implied certification and materiality when billing the government. U.S. ex rel. Schutte v. SuperValu Inc. (2023): Established that subjective intent (scienter) governs fraud. Subjectively suspecting non-compliance while claiming an "objectively reasonable interpretation" or maintaining "willful blindness" constitutes fraud. 3. The Five Compliance Buckets Bucket 1: Sourcing Origin: Governed by the Buy American Act (BAA) and Trade Agreements Act (TAA). Bucket 2: Prohibited Sources: Targets restricted entities (Section 889 bans FAR Part 40 Overhaul: A major structural reorganization consolidating supply chain security rules into FAR Part 40. Bucket 3: Cybersecurity & CMMC:Layer 1 (FCI): Basic hygiene under FAR 52.204-21. Layer 2 (CUI): 110 security controls under DFARS 252.204-7012 / NIST SP 800-171, 72-hour incident reporting, and FedRAMP moderate equivalency for cloud providers. Layer 3 (CMMC): Independent verification by accredited C3PAOs. Phase 2 mandates third-party certification at contract award. Strategy: Use data minimization (redacting/descoping technical drawings) to prevent radioactive CUI from ever crossing foreign firewalls. Bucket 4: Labor & Ethics: Governed by FAR 52.222-50, Section 307 of the Tariff Act, and the Uyghur Forced Labor Prevention Act (UFLPA), which enforces a rebuttable presumption of forced labor. Enforces the employer pays principle against debt bondage from recruitment fees. Leverage existing European compliance frameworks like Germany's LKSG. Bucket 5: Foreign Legal Friction: Unsanctioned network penetration testing in Germany violates StGB Section 202A/202B (data espionage). Transferring employee logs triggers GDPR constraints and German Works Council co-determination rights under Section 87. 4. The 8-Step Practical Audit Playbook 5. Emerging Threat: AI-Generated Compliance