From 3386022b0137e2dd8e52545497e9d87da1c3455c Mon Sep 17 00:00:00 2001 From: ImanABS Date: Fri, 20 Dec 2024 22:24:49 +0100 Subject: [PATCH] ITAR Compliance Program Guidelines (#1213) --- .../itar compliance program guidelines.yaml | 5862 +++++++++++++++++ .../ITAR Compliance Program Guidelines.xlsx | Bin 0 -> 70861 bytes 2 files changed, 5862 insertions(+) create mode 100644 backend/library/libraries/itar compliance program guidelines.yaml create mode 100644 tools/ITAR/ITAR Compliance Program Guidelines.xlsx diff --git a/backend/library/libraries/itar compliance program guidelines.yaml b/backend/library/libraries/itar compliance program guidelines.yaml new file mode 100644 index 000000000..f1b3ed0b7 --- /dev/null +++ b/backend/library/libraries/itar compliance program guidelines.yaml @@ -0,0 +1,5862 @@ +urn: urn:intuitem:risk:library:itar-compliance-program-guidelines +locale: en +ref_id: ITAR-Compliance-Program-Guidelines +name: ITAR Compliance Program Guidelines +description: "The guidelines contained in this document are intended to provide an\ + \ overview of an effective compliance program and an introduction to defense trade\ + \ controls, including information on the laws and regulations the U.S. Department\ + \ of State, Bureau of Political-Military Affairs, Directorate of Defense Trade Controls\ + \ (DDTC), administers. These defense trade controls are contained in the Arms Export\ + \ Control Act (AECA) (22 U.S.C. \xA7 2751 et seq.) as amended, and the International\ + \ Traffic in Arms Regulations (ITAR), Title 22 of the Code of Federal Regulations\ + \ in parts 120-130, both of which are authoritative on defense trade controls. \n\ + version 09/15/2023\nLink : https://www.pmddtc.state.gov/ddtc_public/ddtc_public?id=ddtc_kb_article_page&sys_id=4f06583fdb78d300d0a370131f961913 " +copyright: Directorate of Defense Trade Controls +version: 1 +provider: Directorate of Defense Trade Controls +packager: intuitem +objects: + framework: + urn: urn:intuitem:risk:framework:itar-compliance-program-guidelines + ref_id: ITAR-Compliance-Program-Guidelines + name: ITAR Compliance Program Guidelines + description: "The guidelines contained in this document are intended to provide\ + \ an overview of an effective compliance program and an introduction to defense\ + \ trade controls, including information on the laws and regulations the U.S.\ + \ Department of State, Bureau of Political-Military Affairs, Directorate of\ + \ Defense Trade Controls (DDTC), administers. These defense trade controls are\ + \ contained in the Arms Export Control Act (AECA) (22 U.S.C. \xA7 2751 et seq.)\ + \ as amended, and the International Traffic in Arms Regulations (ITAR), Title\ + \ 22 of the Code of Federal Regulations in parts 120-130, both of which are\ + \ authoritative on defense trade controls. \nversion 09/15/2023\nLink : https://www.pmddtc.state.gov/ddtc_public/ddtc_public?id=ddtc_kb_article_page&sys_id=4f06583fdb78d300d0a370131f961913 " + implementation_groups_definition: + - ref_id: DDTC + name: DDTC Suggestions + description: DDTC Suggestions + - ref_id: 7C + name: Sample Audit Checklists + description: Sample Audit Checklists + requirement_nodes: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1 + assessable: false + depth: 1 + ref_id: ELEMENT 1 + name: MANAGEMENT COMMITMENT + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1 + ref_id: ELEMENT 1A + name: Developing and Generating Support for a Culture of Compliance + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a + description: Management commitment is one of the most important factors in creating + a deep-rooted culture of ITAR compliance within organizations. While robust + management commitment alone is insufficient to ensure compliance with all + relevant U.S. export control laws and regulations, it is essential for fostering + a proactive compliance posture. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a + description: "Management includes not only senior management, but also managers\ + \ at all levels within the organization, and the most important stance management\ + \ can take to engender a culture of compliance is to lead by example. Through\ + \ their words and actions, management should encourage compliance and should\ + \ discourage the prioritization of business or other interests over compliance.\ + \ Employees should have a high level of assurance that ITAR compliance is\ + \ management\u2019s greatest priority in all export-related decisions. Management\ + \ should communicate to employees that they are encouraged to raise questions\ + \ or concerns about compliance and potential risk areas and employees will\ + \ not experience retribution or retaliation if they do so. Employees should\ + \ understand that ITAR compliance is everyone\u2019s responsibility within\ + \ the organization." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:3 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a + description: "To help generate support and buy-in among employees, management\ + \ should incorporate compliance into employee performance plans and evaluations.\ + \ Employees should be expected to think about and recommend ways to improve\ + \ compliance and raise concerns when they see a possible problem, and their\ + \ performance plans and evaluations should account for those expectations.\ + \ Additionally, management should recognize and reward employees who speak\ + \ up, even if the problem reported resulted in no specific confirmed violation,\ + \ but perhaps lead to improving the organization\u2019s compliance procedures." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a:4 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1a + description: "In addition, management should communicate to employees that export\ + \ control violations will not be tolerated and may result in disciplinary\ + \ action against the employee, regardless of the employee\u2019s position,\ + \ title, or performance. Management should adopt clear disciplinary procedures\ + \ and consequences for addressing compliance misconduct, should enforce them\ + \ consistently across the organization, and should ensure that they are proportionate\ + \ to the misconduct and appropriate to deter future misconduct." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1 + ref_id: ELEMENT 1B + name: Demonstrating Management Commitment Through Policies and Procedures + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b + description: "Management is ultimately responsible for ensuring its organization\u2019\ + s compliance with the ITAR. Management can demonstrate its commitment to ITAR\ + \ compliance by:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1 + description: Creating and maintaining an ICP; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1 + description: "Providing sufficient resources, including time, funding, personnel,\ + \ and training, to implement and maintain an ICP commensurate with the organization\u2019\ + s risk; and" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:1 + description: Creating and maintaining an Export Compliance Management Commitment + Statement. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b + name: ITAR Compliance Program + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2 + description: "A critical aspect of management\u2019s effort to demonstrate its\ + \ commitment to compliance with the ITAR is creating and maintaining an ICP.\ + \ An effective ICP should be:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1 + description: In writing and clearly state the organizations ITAR compliance + policies and procedures; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1 + description: "Specifically tailored to an organization\u2019s ITAR-controlled\ + \ activities and its areas of risk;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1 + description: Regularly reviewed and updated by various business departments + responsible for complying with the ITAR; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:1 + description: Fully supported by management. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:2 + description: When developing an ICP, management should identify areas that could + potentially pose a risk of ITAR violations and the lines of authority, e.g., + direct, indirect, and unofficial, in those areas that can assist in preventing + ITAR violations. After an ICP is established, management should remain actively + engaged in improving the compliance program, e.g., by attending periodic ICP + resource and planning meetings at which employees can discuss any ITAR compliance + deficiencies they have identified or propose changes to enhance the ICP. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b + name: Sufficient Compliance Resources + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:3 + description: "Management should provide compliance personnel with adequate resources,\ + \ including the appropriate training, funding, human capital, organizational\ + \ support, information technology resources, and other resources to fulfill\ + \ their responsibilities and implement an effective ICP. In assessing whether\ + \ such resources are adequate, management should take account of the organization\u2019\ + s size, scope of operations, and overall risk profile." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b + name: Export Compliance Management Commitment Statement + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4 + description: 'Another critical way to demonstrate strong management support + for ITAR compliance is to have the Chief Executive Officer, President, or + other senior executives personally sign an Export Compliance Management Commitment + Statement that is communicated to employees through all appropriate channels, + including in the opening pages of an ITAR Compliance Manual, on the corporate + website, and through periodic email reminders to all employees. The organization + should review and disseminate this statement at least annually for all employees + and, as appropriate, all contractors to read and sign. The statement should:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: "Underscore the organization\u2019s commitment to export compliance\ + \ and providing sufficient resources to ensure compliance." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: Reference the role and function of the U.S. export control system + and its importance in protecting the foreign policy and national security + of the United States. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: Affirm that no export shall be made under any circumstances that + violates or potentially violates the ITAR. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: "Emphasize the importance of employees understanding the ITAR and\ + \ its impact on their job functions. Employees should also understand specific\ + \ risks of non-compliance regarding an organization\u2019s activities, technologies,\ + \ and export destinations." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: Communicate the importance of routine export compliance monitoring + and auditing. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: "Stress the importance of and/or the requirement to report known\ + \ or suspected violations to the organization\u2019s export compliance department\ + \ anonymously or via an organization\u2019s compliance hotline." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: Reiterate that reporting known or suspected ITAR violations in + good faith will not adversely affect employees. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: Reiterate that reporting known or suspected export violations will + be used to measure job performance. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1b:4:1 + description: Include the name and contact information of the personnel responsible + for responding to ITAR compliance inquiries. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1 + ref_id: ELEMENT 1C + name: Organizing the Compliance Function Appropriately + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c + description: "Management is responsible for deciding where to locate compliance\ + \ personnel within an organization\u2019s structure. This includes establishing\ + \ organizational charts and developing descriptions of the organization\u2019\ + s trade and export compliance functions and determining the extent to which\ + \ the ICP is centralized. The organizational structure should clearly identify\ + \ the following areas of authority:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + description: Who in management is responsible for overseeing the ICP? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + description: Who within the ICP is the point of contact regarding export compliance + questions? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + description: Who within the ICP and/or business functions is responsible for + investigating and identifying the root causes of ITAR violations? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + description: Who within the ICP and/or business functions is responsible for + overseeing and implementing corrective actions? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + description: Who within the ICP is responsible for drafting, finalizing, and + submitting export-related documents to DDTC? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + description: Who within the ICP is responsible for sending other communications + regarding export compliance matters to DDTC, if necessary? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:1 + description: Who is responsible for legal interpretation and guidance on internal + export compliance matters? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c + description: "Empowered Officials (EOs) typically handle at least some of the\ + \ responsibilities listed above. As set forth in ITAR \xA7 120.67, some of\ + \ the primary attributes and responsibilities of an EO include, but are not\ + \ limited to:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2 + description: Direct employment by an organization in a position having authority + for policy or management within the organization + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2 + description: Written legal empowerment to sign license applications and other + requests for approval on behalf of the organization. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2 + description: Understanding the provisions and requirements of the various export + control statutes and regulations and the criminal liability, civil liability, + and administrative penalties for violating the AECA and the ITAR. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2 + description: 'Independent authority to:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4 + description: Inquire into any aspect of a proposed export, temporary import, + or brokering activity by the organization; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4 + description: Verify the legality of the transaction and the accuracy of the + information to be submitted to DDTC; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:2:4 + description: Refuse to sign any license application or other request for approval + without prejudice or adverse recourse. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c:3 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-1c + description: Management is responsible through training and hiring practices + for ensuring that compliance personnel possess the requisite technical knowledge, + expertise, and experience to effectively implement the ICP. Management should + also ensure that compliance personnel, including the EO, are delegated sufficient + authority and autonomy to implement the ICP, consistent with their responsibilities. + Management should hold routine and periodic meetings with the EO to ensure + that employees are following ITAR policies and procedures. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + assessable: false + depth: 1 + ref_id: ELEMENT 2 + name: DDTC REGISTRATION, JURISDICTION & CLASSIFICATION, AUTHORIZATIONS, & OTHER + ITAR ACTIVITIES + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + ref_id: ELEMENT 2A + name: Registration + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a + description: The ICP should include information on registration requirements + in the ITAR. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a + name: Who Needs to Register? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2 + description: "The organization\u2019s ICP should explain who is required to\ + \ register with DDTC. The ITAR sets forth the general requirements to register\ + \ for manufacturers, exporters, and temporary importers in ITAR part 122 and\ + \ for brokers in ITAR part 129, while also imposing registration requirements\ + \ in certain unique circumstances. See, e.g., ITAR \xA7\xA7 126.16(k) and\ + \ 126.17(k) regarding requirements for intermediate consignees under the Australia\ + \ and UK treaties, respectively." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2 + description: The ITAR requires that, subject to certain exemptions, any person + who engages in the United States in the business of manufacturing or exporting + or temporarily importing defense articles, including technical data, or furnishing + defense services, must register with DDTC. Manufacturers who do not engage + in exporting must nevertheless register. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2 + description: The ITAR also requires that, subject to certain exemptions, persons + engaged in brokering activities with respect to the manufacture, export, import, + or transfer of any foreign defense article or defense service must register + with DDTC. The brokering registration requirement applies to any U.S. person, + any foreign person located in the United States, and any foreign person located + outside of the United States and owned or controlled by a U.S. person. A manufacturing + registration does not satisfy brokering registration requirements and vice + versa, and persons engaged in both manufacturing and brokering activities + must register as both a manufacturer and broker. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:4 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2 + description: The purpose of registration is primarily to provide the U.S. Government + with visibility into who is involved in ITAR-controlled activities. Registration + does not confer any export, temporary import, or brokering rights or privileges. + Registration also does not constitute a certification of ITAR compliance or + indicate the effectiveness of an ICP. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2:5 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:2 + description: "Registration is generally a precondition to the issuance of any\ + \ license or other approval, including the use of certain license exemptions.\ + \ Additional DDTC registration information and FAQs can be found on DDTC\u2019\ + s website." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a + name: Types of Registration + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:3:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:3 + description: 'There are three types of registration: manufacturer, exporter, + and broker. Organizations can apply as a manufacturer, exporter, and/or broker + in one registration application. They will receive a code that corresponds + with their registration type and a completion letter from the DDTC under their + account after payment (currently via Defense Export Control and Compliance + System (DECCS)).' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a + name: Submitting Registration Applications and Renewals + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:4 + description: "A prospective registrant must electronically submit a Statement\ + \ of Registration (Department of State form DS-2032) to the Office of Defense\ + \ Trade Controls Compliance (DTCC) by following the submission guidelines\ + \ available on the DDTC website and referring to the requirements set forth\ + \ in ITAR \xA7 122.2. Registrations are valid for 12 months and must be renewed\ + \ annually. The expiration date is included in the registration letter issued\ + \ by DDTC. Registration renewal submissions should be submitted through DECCS\ + \ up to a maximum of 60 days but no less than 30 days in advance of the renewal\ + \ expiration." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a + name: Registration Changes and Notifications + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5 + description: 'Registrants are required to notify DDTC within a specified time + period, e.g., five or 60 days, when certain changes in their organization + occur. Changes that require notification to DDTC include, but are not limited + to, when:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1 + description: Certain persons related to the organization have been indicted + or otherwise charged with or convicted of violating certain criminal statutes. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1 + description: Organizations change certain information in the Statement of Registration, + such as name, address, ownership, or persons listed on registration. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1 + description: Organizations intend to sell or transfer ownership or control to + a foreign person. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:1 + description: Organizations are part of acquisitions or mergers. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:5 + description: "Additional notification requirements are found in ITAR \xA7 122.4." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a + name: DDTC Registration Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6 + description: "Organizations often submit voluntarily disclosures pursuant to\ + \ ITAR \xA7 127.12 regarding their failure to notify DDTC of registration\ + \ changes required under the ITAR. To reduce the risk of these types of ITAR\ + \ violations from occurring, DDTC recommends that organizations take the following\ + \ actions:" + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1 + description: Understand which activities require an organization to register + with DDTC and determine whether the organization is required to do so. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1 + description: Assign a senior officer to oversee the registration process and + to sign the required notifications. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1 + description: Establish and implement policies and procedures to ensure the complete + and timely submission of registration renewals and required notifications + for material changes. For example, create policies and procedures to ensure + that export compliance personnel are informed in advance of changes in senior + officers and mergers and acquisitions to ensure timely updates to the registration + statement. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2a:6:1 + description: ' Protect registration codes, which are specific to the registrant + and should not be made available publicly.' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + ref_id: ELEMENT 2B + name: Jurisdiction and Classification + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b + description: To determine whether organizations or individuals need to register + or obtain a DDTC license or other approval, they must determine the appropriate + jurisdiction and classification of the commodities they manufacture, export, + temporarily import, or broker. Jurisdiction refers to the set of regulations + to which a commodity is subject, e.g., the ITAR or the Export Administration + Regulations (EAR), whereas classification refers to the specific entry on + the respective control list under which the commodity is described, e.g., + USML Category VIII(a)(2), or Commerce Control List Export Control Classification + Number ECCN 9A610.a). + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b + name: Commodity Jurisdiction Requests + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2 + description: "Manufacturers, exporters, and temporary importers may self-classify\ + \ their items and services. However, if after reviewing the Order of Review\ + \ described in ITAR \xA7 120.11, doubt remains regarding the jurisdiction\ + \ and/or classification of an item or service, organizations may submit a\ + \ Commodity Jurisdiction (CJ) determination request to DDTC as described in\ + \ ITAR \xA7 120.12 for an authoritative determination." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:2 + description: "To submit a CJ request, navigate to DDTC\u2019s website and under\ + \ \u201CConduct Business\u201D for instructions on how to submit a Form DS-4076\ + \ electronically via DECCS. Please note that a supporting letter from the\ + \ original equipment manufacturer (OEM) is generally required for CJ applications\ + \ by persons other than the OEM." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b + name: DDTC Jurisdiction and Classification Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3 + description: 'Organizations routinely disclose to DDTC ITAR violations resulting + from improper jurisdiction and classification. To reduce the risk of these + types of ITAR violations from occurring, DDTC recommends that organizations + take the following actions:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: If any doubt exists regarding the proper jurisdiction or classification, + err on the side of caution, and submit a CJ request to DDTC. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: Understand the form and fit of the articles, as well as the function + and performance capability of the articles. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: Document the design and development process for new products and + monitor and document modifications to existing products. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: Designate employees with the necessary technical expertise, e.g., + engineers or program managers, and export controls personnel to perform jurisdiction + and classification review functions. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: Establish formal written policies and procedures for reviewing + and documenting jurisdiction and classification decisions. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: "Develop a system of tracking and marking jurisdiction and classification\ + \ determinations at the time \u2013 or as soon as possible after \u2013 commodities\ + \ are manufactured." + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: DDTC routinely updates USML categories, so organizations should + consistently monitor these updates and adjust their internal jurisdiction + and classification determinations accordingly. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: If a CJ request is pending, DDTC recommends treating the commodity + as defense article or a defense service until DDTC issues the CJ determination. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2b:3:1 + description: Keep records of all jurisdiction and classification decisions in + a central location that can easily be accessed, reviewed, referred to, and + updated. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + ref_id: ELEMENT 2C + name: Authorizations + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c + description: "DDTC authorization via a license or other approval is required\ + \ prior to engaging in any ITAR-controlled export (see ITAR \xA7 120.50),\ + \ reexport (see ITAR \xA7 120.51), retransfer (see ITAR \xA7 120.52), temporary\ + \ import (see ITAR 120.53), or brokering activities (see ITAR 129.2(b))." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c + name: Licenses, Agreements, and Other Approvals + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2 + description: "As defined in the ITAR, a \u201Clicense\u201D is a document bearing\ + \ the word \u201Clicense\u201D that is issued by DDTC that permits the export,\ + \ reexport, retransfer, temporary import, or brokering of a specific defense\ + \ article or defense service controlled under the ITAR." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2 + description: "An \u201Cother approval\u201D is a document, other than a license,\ + \ issued by DDTC that approves an ITAR-controlled activity or the use of an\ + \ exemption to the license requirements in the ITAR. License exemptions are\ + \ therefore considered a form of DDTC authorization. Additional information\ + \ about obtaining a license or other approval from DDTC can be found on DDTC\u2019\ + s website. Licenses are submitted and tracked in DECCS." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2 + description: 'Agreements approved by the Office of Defense Trade Controls Licensing + (DTCL) may authorize U.S. persons to furnish defense services and export technical + data to foreign persons, manufacture defense articles abroad, or establish + distribution points abroad for defense articles of U.S. origin for subsequent + distribution to foreign persons or entities. Agreements are submitted and + tracked in DECCS. There are three different types of agreements that cover + these activities:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3:1 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3 + description: 'Manufacturing Licensing Agreements (MLA): agreements whereby a + U.S. person grants a foreign person an authorization to manufacture defense + articles abroad and that involve or contemplate either the export of technical + data or defense articles or the performance of a defense service; or the use + by the foreign person of technical data or defense articles previously exported + by the U.S. person.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3:2 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3 + description: 'Technical Assistance Agreements (TAA): agreements for the performance + of a defense service(s) or the disclosure of technical data, as opposed to + an agreement granting a right or license to manufacture defense articles.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3:3 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:3 + description: 'Distribution Agreements: agreements to establish a warehouse or + distribution point abroad for defense articles exported from the United States + for subsequent distribution to entities in an approved sales territory.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2:4 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:2 + description: "Additional information on agreements can be found on DDTC\u2019\ + s website and under ITAR part 124. Guidance for preparing agreements can be\ + \ found on DDTC\u2019s website in the Agreement Guidance section, and further\ + \ detail is provided in the DDTC\u2019s Guidelines for Preparing Agreements." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c + name: Reexports, Retransfers, and General Correspondence Requests + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3 + description: Prior written DDTC approval must be obtained before reselling, + transferring, reexporting, retransferring, transshipping, or disposing of + a defense article to any end user, end use, or destination other than as stated + on the export license or in the Electronic Export Information filing for any + exemption previously claimed. This requirement applies in all circumstances, + except where the transaction is in accordance with the provisions of an exemption + that explicitly authorizes the resale, transfer, reexport, retransfer, or + disposition of a defense article without such approval. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3 + description: U.S. and foreign persons may submit a written request for approval + of a reexport or retransfer of defense articles or technical data to DTCL + through DECCS. This request is typically referred to as a General Correspondence + (GC) request. Foreign persons may also submit GC requests regarding reexports, + retransfers, or changes in end use to DTCL, and they do not need to be registered + with DDTC in order to do so. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3:3 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:3 + description: Additional information about approvals for reexports or retransfers + can be found in ITAR part 123. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c + name: DDTC Licenses, Agreements, and Exemptions Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4 + description: 'To reduce the risk of ITAR violations related to obtaining and + using licenses, agreements, and exemptions, DDTC recommends that organizations + establish policies and procedures for the following:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Incorporating licensing and other authorization considerations + in all appropriate organization processes. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Anticipating, to the extent possible, the need for licenses in + advance of proposed export activities. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Ensuring that business development, sales, and marketing personnel + understand timelines for obtaining licenses. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Ensuring ample time to draft, submit, and receive approval for + agreements. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Ensuring all parties understand appropriate terms, conditions, + and provisos of the agreement, and conducting periodic audits of export activities + under the agreement. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Performing as much fact finding as practicable ahead of submitting + license applications and anticipating changes that may occur while a license + is valid, e.g., change in freight forwarder, potential U.S. or foreign subcontractors + involved in the transaction, or changes in the end use or end user. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Reviewing for restrictions on parties to the transaction, including + by screening through the Consolidated Screening List. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: ' Creating, submitting, tracking and disposition of licenses and + other authorizations.' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Successfully implementing agreements (e.g., internal controls, + technology control plans, identifying foreign person status, and employment + status of meeting attendees). + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:10 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Communicating with all foreign parties to determine who will be + involved in the transaction and their roles, e.g., recipients of services, + providers, subcontractors. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:11 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: ' Working with foreign parties to understand if there will be dual + or third- country national employees working on the proposed activities and + how the foreign party will screen those individuals.' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:12 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Ensuring foreign parties have compliance safeguards in place to + protect any technical data transferred under the agreements from unauthorized + access. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:13 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Protecting against unauthorized release of technical data to foreign + entities and foreign employees. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:14 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Assessing all conditions that must be satisfied to qualify for + use of any license exemption. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1:15 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:4:1 + description: Reviewing and approving use of license exemptions by appropriate + compliance personnel. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c + name: 'DDTC Reexports, Retransfers, and General Correspondence Requests + + Suggestions' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5 + description: 'To reduce the risk of ITAR violations related to the reexport + or retransfer of defense articles from occurring, DDTC recommends that organizations + take the following actions:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1 + description: Establish policies and procedures for reviewing and obtaining authorization + for reexports and retransfers. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1 + description: Establish policies and procedures for tracking and keeping records + regarding export authorizations for reexports or retransfers. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1 + description: Ensure understanding of the difference between requesting an initial + export authorization and a subsequent reexport or retransfer approval. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1 + description: Gather all relevant information about the transaction prior to + requesting written approval to ensure the request is not returned without + action by DDTC due to lack of information. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2c:5:1 + description: Educate foreign recipients of U.S. defense articles about end use + and other ITAR requirements. For example, foreign recipients should understand + that destruction is considered a change in end use, and they must request + approval from DDTC in advance of destruction or demilitarization. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + ref_id: ELEMENT 2D + name: Restricted Party Screening + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d + description: "An organization should screen all parties involved in a transaction\ + \ prior to engaging in any ITAR-controlled activity with such parties. This\ + \ includes screening such parties through the Consolidated Screening List\ + \ (CSL) or restricted party screening tools containing CSL information. The\ + \ CSL is a list that U.S. government agencies, including the Departments of\ + \ State, Commerce, and the Treasury, maintains restrictions on certain exports,\ + \ reexports, or transfers of items. U.S. government agencies routinely update\ + \ their lists, which are consolidated in the CSL, and DDTC encourages routine\ + \ screening against the CSL to avoid prohibited transactions. Information\ + \ on screening and the CSL can be found on the International Trade Administration\u2019\ + s website." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d + name: Proscribed Countries + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:2:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:2 + description: "It is the policy of the U.S. Government to deny licenses for exports\ + \ and imports of defense articles and defense services destined for or originating\ + \ in certain countries listed in ITAR \xA7 126.1, subject to certain exceptions.\ + \ DDTC considers unauthorized transactions with proscribed countries to be\ + \ serious violations of the ITAR. More information on the types of prohibited\ + \ exports, imports, and sales to or from specific countries can be found in\ + \ ITAR \xA7 126.1." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d + name: DDTC Restricted Party Screening and Proscribed Countries Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3 + description: 'To ensure effective screening and reduction of the risk of ITAR + violations involving restricted parties and proscribed countries, DDTC recommends + that organizations take the following actions:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + description: "Establish policies and procedures for implementing screening within\ + \ the organization\u2019s operations. For example, consider establishing procedures\ + \ for screening prior to each of the following activities: entering substantive\ + \ business discussions, signing contracts or other agreements, submitting\ + \ license applications, and exporting." + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + description: Establishing policies and procedures for resolving positive hits + and reviewing questionable transactions. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + description: Determine the frequency of routine screening and rescreening of + customers, suppliers, or other entities engaged in on-going transactions. + Frequency may differ depending on risk related to jurisdiction, industry, + entity, etc. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + description: Maintain detailed screening record results. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + description: Dedicate adequate resources for screening. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + description: Monitor updates to U.S. Government lists. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2d:3:1 + description: "Ensure that all relevant employees understand which destinations\ + \ are proscribed under ITAR \xA7 126.1 and the potential consequences of exporting\ + \ without authorization to one of those destinations." + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + ref_id: ELEMENT 2E + name: Brokering + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e + description: "ITAR \xA7 129.1(a) states that,\u201Cpersons engaged in the business\ + \ of brokering activities shall register and pay a registration fee and that\ + \ no person may engage in the business of brokering activities without a license.\u201D" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e + description: "A broker, as defined in ITAR \xA7 129.2(a), is any person who\ + \ engaged in brokering activities who is also U.S. person wherever located,\ + \ any foreign person located in the United States, or any foreign person located\ + \ outside the United States that is owned or controlled by a U.S. person." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e + description: "Brokering activities, as defined by ITAR \xA7 129.2(b), mean any\ + \ action on behalf of another to facilitate the manufacture, export, permanent\ + \ import, transfer, reexport, or retransfer of a U.S. or foreign defense article\ + \ or defense service, regardless of its origin. Such activities include, but\ + \ are not limited to:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:3:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:3 + description: Financing, insuring, transporting, or freight forwarding defense + articles and defense services. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:3:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:3 + description: Soliciting, promoting, negotiating, contracting for, arranging, + or otherwise assisting in the purchase, sale, transfer, loan, or lease of + a defense article or defense service. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e + name: Authorization Requirements + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4 + description: "ITAR \xA7 129.4 provides a list of defense articles and defense\ + \ services for which a broker must obtain written approval from DDTC prior\ + \ to engaging in brokering activities. A broker may request DDTC approval\ + \ for brokering activities by submitting a completed Form DS-4294 in DECCS.\ + \ The organization must describe in the request the who, what, where, when,\ + \ and why of the transaction. A full list of required information can be found\ + \ in ITAR \xA7 129.6." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4 + description: "Brokers can find exemptions to brokering requirements in ITAR\ + \ \xA7 129.5. Exempt activities include:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4:2:1 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4:2 + description: "Certain brokering activities undertaken for an agency of the U.S.\ + \ Government, as described in ITAR \xA7 129.5(a)." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4:2:2 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4:2 + description: "Certain brokering activities involving foreign defense articles\ + \ or defense services arranged wholly within and destined exclusively for\ + \ the North Atlantic Treaty Organization (NATO), NATO countries, Australia,\ + \ Israel, Japan, New Zealand, or the Republic of Korea, as described in ITAR\ + \ \xA7 129.5(b)." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4:3 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:4 + description: "These brokering exemptions do not apply if the transaction involves\ + \ ITAR \xA7 126.1 countries or parties debarred pursuant to ITAR \xA7 127.7,\ + \ as set forth in ITAR \xA7 129.7." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e + name: Annual Brokering Activities Report Requirement + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:5:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:5 + description: "Any person who engages in brokering activities is required to\ + \ provide to DDTC on an annual basis a report of their brokering activities\ + \ in the previous 12 months. Reports must be submitted along with the broker\u2019\ + s annual renewal submission or, if not renewing, within 30 days after expiration\ + \ of registration. The information required for these reports can be found\ + \ in ITAR \xA7 129.10." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e + name: DDTC Brokering Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6 + description: 'To reduce the risk of brokering-related ITAR violations, DDTC + recommends that brokers take the following actions:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1 + description: Establish policies and procedures for obtaining prior authorization + for brokering activities, reporting brokering activities, and maintaining + records regarding brokering activities. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1 + description: Understand which activities constitute brokering activities under + the ITAR and identify whether and to what extent the broker is engaged in + such activities. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1 + description: Review and understand the available exemptions to the brokering + authorization requirements. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2e:6:1 + description: Submit annual brokering reports to DDTC on time. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + ref_id: ELEMENT 2F + name: Political Contributions, Fees, and Commissions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f + description: Applicants and suppliers or vendors need to report to DDTC certain + political contributions, fees, or commissions relating to sales of defense + articles or defense services valued at $500,000 or more that are being sold + commercially to or for the use of the armed forces of a foreign country or + international organization. More information can be found in ITAR part 130. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f + description: 'A reportable fee or commission is any loan, gift, donation, or + other payment of $1,000 or more made, or offered or agreed to be made directly + or indirectly, whether in cash or in kind, and whether pursuant to a written + contract, that is:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:2 + description: To or at the direction of any person, irrespective of nationality, + whether employed by or affiliated with an applicant, a supplier, or a vendor; + and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:2 + description: For the solicitation or promotion or otherwise to secure the conclusion + of a sale of defense articles or defense services to or for the use of the + armed forces of a foreign country or international organization. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f + description: 'The phrase fee or commission does not include:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3 + description: "A political contribution or a payment excluded by ITAR \xA7 130.6\ + \ from the definition of political contribution;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3 + description: A normal salary (excluding contingent compensation) established + at an annual rate and paid to a regular employee of an applicant, supplier, + or vendor; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3 + description: General advertising or promotional expenses not directed to any + sale or purchaser; or + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:3 + description: "Payments made, or offered or agreed to be made, solely for the\ + \ purchase by an applicant, supplier, or vendor of specific goods or technical,\ + \ operational, or advisory services, when such payments are not disproportionate\ + \ in amount with the value of the specific goods or services furnished. See\ + \ ITAR \xA7 130.5(b)." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f + description: 'Political contribution means any loan, gift, donation, or other + payment of $1,000 or more made, or offered or agreed to be made, directly + or indirectly, whether in cash or in kind, which is:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:4:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:4 + description: To or for the benefit of, or at the direction of, any foreign candidate, + committee, political party, political faction, or government or governmental + subdivision, or any individual elected, appointed or otherwise designated + as an employee or officer thereof; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:4:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:4 + description: "For the solicitation or promotion or otherwise to secure the conclusion\ + \ of a sale of defense articles or defense services to or for the use of the\ + \ armed forces of a foreign country or international organization. Taxes,\ + \ customs duties, license fees, and other charges required to be paid by applicable\ + \ law or regulation are not regarded as political contributions. See ITAR\ + \ \xA7 130.6." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f + name: Reporting + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5 + description: "To determine whether a report needs to be provided to DDTC under\ + \ ITAR part 130, applicants (as defined in ITAR \xA7 130.2) and suppliers\ + \ (as defined in ITAR \xA7 130.7) must conduct their due diligence with respect\ + \ to their vendors (as defined in ITAR \xA7 130.8). Applicants and suppliers\ + \ should request the information listed in ITAR \xA7 130.10, which includes\ + \ any political contributions, fees, or commissions paid or offered or agreed\ + \ to be paid with respect to the sale. See ITAR \xA7 130.12 and ITAR \xA7\ + \ 130.13 for more on the information to be furnished by applicants, suppliers,\ + \ and their vendors." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5 + description: 'Each applicant or supplier must inform DDTC as to whether the + applicant, suppliers, or their vendors have paid, or offered or agreed to + pay:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:2:1 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:2 + description: Political contributions in an aggregate amount of $5,000 or more. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:2:2 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:2 + description: "Fees or commissions in an aggregate amount of $100,000 or more.\ + \ If so, the applicant must furnish to DDTC the information specified in ITAR\ + \ \xA7 130.10." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:2:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:2 + description: "Any payments or offers or agreements to make payments of political\ + \ contributions or fees or commissions that the applicant or supplier learns\ + \ of after submission of the license application and any value changes to\ + \ previously submitted reports must be submitted as a supplement report and\ + \ must include a detailed statement of the reasons why the applicant or supplier\ + \ did not furnish the information at the time of the application. See ITAR\ + \ \xA7 130.11 for information regarding supplementary reports." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5:3 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:5 + description: "See ITAR \xA7 130.10 for a full list of the required information\ + \ to be submitted in a report to DDTC." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f + name: DDTC Political Contributions, Fees, and Commissions Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6 + description: 'To reduce the risk of ITAR part 130-related violations, DDTC recommends + that organizations take the following actions:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6:1 + description: Understand whether you or your vendors are involved in paying political + contributions, fees, or commissions. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6:1 + description: Understand what information needs to be asked of and received from + your vendors. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2f:6:1 + description: Establish policies and procedures for accurate and accessible recordkeeping + of such political contributions, fees, or commissions. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2 + ref_id: ELEMENT 2G + name: Cybersecurity and Encryption + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g + description: Although the ITAR does not explicitly require organizations to + implement specific cyber security or encryption measures for the storage or + transmission of technical data, cyber intrusion events, and the theft of technical + data may result in unauthorized exports. Other U.S. Government agencies and + programs, however, have specific cyber security requirements. DDTC expects + organizations to take steps to protect their technical data from cyber intrusions + and theft and consider carefully what cyber security solutions work most effectively + for them. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g + description: Having specific policies, procedures, and tools for the encryption + of technical data is a critical part of cyber security. Organizations should + consider both how to encrypt the storage and transmission of technical data + externally, including via cloud and other remote storage, and how to appropriately + encrypt technical data on portable devices. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g + description: "For further information on activities that are not exports, reexports,\ + \ retransfers, or temporary imports related to the sending, taking, or storing\ + \ of technical data, see ITAR \xA7 120.54." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g + name: DDTC Cybersecurity and Encryption Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4 + description: 'To reduce the risk of ITAR violations and improve cyber security + measures, DDTC recommends that organizations take the following actions:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Establish policies and procedures for recurring training on travel + with mobile devices for new and existing employees. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Ensure foreign person employees do not receive unauthorized access + to technical data. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: "Ensure technical data is not backed up to servers in foreign locations,\ + \ unless it meets the criteria set out in ITAR \xA7 120.54(a)(5) regarding\ + \ storage of unclassified technical data secured using end-to-end encryption." + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: ' Coordinate with IT to implement intrusion detection systems.' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Educate employees about phishing, malware, and other cyber threats. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Review electronic storage options, such as cloud storage services, + and understand how service providers protect ITAR-controlled technical data. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Establish security policies for file sharing and collaboration + tools. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Establish measures for encryption of data on mobile devices, such + as laptops and cell phones. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Establish policies and procedures for the review and approval of + employee travel with mobile devices. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1:10 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-2g:4:1 + description: Ensure that IT logs and controls access to company networks that + contain ITAR-controlled technical data by authorized personnel. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3 + assessable: false + depth: 1 + ref_id: ELEMENT 3 + name: RECORDKEEPING + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3 + ref_id: ELEMENT 3A + name: ITAR Recordkeeping Requirements + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a + description: 'The ITAR requires all registrants to maintain records regarding + the manufacture, acquisition, and disposition of defense articles, including + technical data; the provision of defense services; brokering activities; and + information on political contributions, fees, and commissions furnished or + obtained, pursuant to ITAR part 130. The ITAR requires that such records are:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1 + description: Reproducible in paper format, if digital; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1 + description: Legible and readable; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1 + description: Unaltered once recorded or, if altered, with any alterations properly + recorded, including who made them and when; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1 + description: Readily accessible if digital images; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:1 + description: Maintained for a period of five years from the expiration of the + license or other approval, to include exports using an exemption, or from + the date of the transaction. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a + description: 'The following records must be maintained:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: License or other approval; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: License exemption; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Technical data exports; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Oral, visual, or electronic exports; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Certain information related to special comprehensive export authorizations; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Related to the Defense Trade Cooperation Treaty between the United + States and Australia; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Related to the Defense Trade Cooperation Treaty between the United + States and the United Kingdom; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Related to exemptions involving employees who are dual and third- + country nationals; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:9 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Related to voluntary disclosures; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:10 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Brokering recordkeeping requirements; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2:11 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3a:2 + description: Related to political contributions, fees, and commissions. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3 + ref_id: ELEMENT 3B + name: Establishing Recordkeeping Roles and Responsibilities + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b + description: "For each transaction or activity type, organizations should determine\ + \ which records must be maintained pursuant to the ITAR\u2019s recordkeeping\ + \ requirements and develop a list of those records. Based on the list, organizations\ + \ should develop written policies and procedures to ensure that these records\ + \ are maintained properly. Such written policies and procedures should clearly\ + \ articulate who within the organization is responsible for the various recordkeeping\ + \ responsibilities. They should also include, but are not limited to, the\ + \ following:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + description: Establishing policies and procedures for recordkeeping and for + timely destruction of records, or their maintenance past required dates where + relevant to ongoing matters, including, e.g., disclosures to DDTC. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + description: Determining how and where records will be maintained. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + description: Determining how and when records will be inspected for completeness, + accuracy, and quality. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + description: Developing and maintaining processes for managing records by identifying + classes of records and logs of record creators and keepers. If appropriate, + maintain a detailed log or index of records of more sensitive records. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + description: Establishing record-retention requirements for emails, contracts + with freight forwarders, brokers, and distributors, and other records. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + description: Creating recordkeeping redundancies, such as backup IT servers, + where appropriate. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:1 + description: Ensuring that recordkeeping methods do not allow for unrecorded + alterations. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b + description: Organizations should clearly allocate responsibilities for recordkeeping + among personnel in business units, records management, information technology, + system administration, and other offices within the organization. Organizations + should also identify personnel designated with recordkeeping responsibilities + and ensure that oversight of such personnel exists to confirm they are adequately + performing their recordkeeping responsibilities. Finally, organizations should + develop ongoing training and awareness programs to ensure personnel involved + in the recordkeeping process can effectively comply with ITAR recordkeeping + requirements. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b + description: 'Organizations should ensure that every employee involved in ITAR-controlled + activities is trained on how to:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3 + description: Identify and preserve relevant records; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3 + description: Share and retrieve relevant records; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3 + description: Properly dispose of hard drives, thumb drives, and other portable + media devices on which records are stored; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:3 + description: Maintain a backup system for preserving relevant records. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b:4 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3b + description: Organizations should ensure that all required records are captured + and correctly filed to allow for efficient search and retrieval by conducting + periodic audits on the recordkeeping system. Management should also communicate + the importance of recordkeeping to all employees and ensure that sufficient + resources exist to allow employees to perform their recordkeeping duties. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3 + ref_id: ELEMENT 3C + name: Recordkeeping and Technology Control Plans + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c + description: "Organizations that possess technical data and either employ foreign\ + \ persons or conduct frequent meetings with foreign persons should consider\ + \ creating and maintaining a Technology Control Plan (TCP). A TCP sets out\ + \ an organization\u2019s policies and procedures for protecting technical\ + \ data and includes the following elements:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1 + description: Management commitment; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1 + description: Personnel-screening procedures; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1 + description: A physical security plan; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1 + description: An information security plan; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:1 + description: Training and awareness programs. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c + description: A TCP can help reduce the risk of inadvertent ITAR violations through + telephone, facsimile, electronic mail, social media, or in-person exchanges, + particularly during informal technical exchanges with foreign persons. Organizations + can implement a TCP in several ways, including for an organization, a location, + or a defined project. Organizations should incorporate TCP requirements into + their ICP and ensure impacted employees are aware of specific TCP requirements. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c + description: 'TCPs should also address how organizations will keep records regarding + foreign- person visitors at their facilities. For example, organizations could + document all foreign person visits and any special conditions attached to + the visits. Such records should indicate:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3 + description: "The visitor\u2019s name and nationality or nationalities;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3 + description: The name and affiliation of the organization represented; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3 + description: The date of the visit; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3 + description: Persons, physical areas, and room numbers visited; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3 + description: Purpose of the visit with specific emphasis on products or services + discussed; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:3 + description: A summary of the visit, including any issues or circumstances of + note. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:4 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c + description: In addition to documenting these interactions with foreign persons, + TCPs should address how organizations will collect and store human resources + records for foreign person employees involved in ITAR-controlled activities. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3c + description: Instituting these recordkeeping practices through a TCP may also + have the additional benefit of increasing awareness among employees that certain + types of interactions with foreign persons create risk areas for potential + ITAR violations, thereby minimizing the risk of an inadvertent violation. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3 + ref_id: ELEMENT 3D + name: Recordkeeping and Voluntary Disclosures + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d + description: Establishing and implementing robust recordkeeping policies and + procedures are foundational to establishing a strong ICP. In the event an + ITAR violation occurs, thorough documentation is essential for submitting + a voluntary disclosure to DDTC that meets the requirements in ITAR part 127. + Without strong recordkeeping policies and procedures, organizations may find + it difficult to provide all information and documentation described in ITAR + part 127 for voluntary disclosures and to respond to any questions that DDTC + may have regarding the violation. A failure to maintain or produce relevant + records in certain circumstances constitutes an ITAR violation. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d + name: DDTC Recordkeeping Suggestions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2 + description: 'DDTC recommends that organizations identify and implement best + practices for recordkeeping including, but not limited to, the following:' + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: In the event records include copies of exported technical data, + ensuring the records are properly secured, including through encryption for + digital records, to prevent unauthorized access. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: Before employees depart an organization, ensuring any records subject + to ITAR recordkeeping requirements they possess are identified and preserved. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: Evaluating the physical storage site and control procedures for + disposal of records to minimize the risk of losing records or failing to properly + secure technical data. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: Implementing a backup system for electronic storage and implementing + measures that will assist in the recovery of information and other electronic + communications on computer systems if the primary computer system fails. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: Maintaining thorough records of non-disclosure agreements and screenings + involving dual and third-country national employees, as appropriate + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: "Maintaining copies of relevant records that exist on a third-party\ + \ organization\u2019s IT systems, such as copies of shipping records from\ + \ freight forwarders, disclosures submitted by outside counsel, or licensing\ + \ information." + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: Acquiring or developing a central IT storage system or database + for relevant records. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: For offsite record storage and destruction, reviewing the contractual + terms to ensure that ITAR-controlled technical data is protected. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: Periodically reevaluating the efficacy of recordkeeping policies + and procedures. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:10 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: Retaining records of any disclosures and any supporting documentation. + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1:11 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-3d:2:1 + description: "Developing and implementing a system to document all communications\ + \ with DDTC officials, including through outside counsel, involving ITAR-related\ + \ matters, which may help ensure continuity and consistency in an organization\u2019\ + s export compliance functions." + implementation_groups: + - DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4 + assessable: false + depth: 1 + ref_id: ELEMENT 4 + name: DETECTING, REPORTING, & DISCLOSING VIOLATIONS + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4 + ref_id: ELEMENT 4A + name: Detect and Report Suspected ITAR Violations Early + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a + description: "Organizations should develop and disseminate policies and procedures\ + \ that provide clear guidance to all employees regarding the detecting and\ + \ reporting of suspected ITAR violations. Because ITAR violations can cause\ + \ serious harm to U.S. national security and foreign policy, they can result\ + \ in the imposition of criminal and/or civil penalties, to include debarment,\ + \ and/or other costs, including reputational damage and the denial or revocation\ + \ of export licenses. Early detection, reporting, and rapid corrective actions\ + \ are essential to minimize any harm to U.S. national security and foreign\ + \ policy and mitigate an organization\u2019s legal exposure." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a + description: 'Organizations should establish policies and procedures to detect, + stop, investigate, confirm, report, and remediate any suspected ITAR violations + immediately. To this end, DDTC recommendations that organizations:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + description: Implement clear internal reporting procedures for employees to + ensure that employees understand that it is their obligation to report suspected + ITAR violations. Organizations should widely promulgate these procedures. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + description: Provide a mechanism through which employees can report suspected + ITAR violations anonymously and confidentially and ensure that employees are + aware of and can effectively use this mechanism. For example, organizations + may remind employees of such reporting mechanisms through regular bulletins + or visual reminders (such as posters) and may provide templates to make reporting + suspected violations efficient and effective. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + description: Clearly identify and communicate to employees the office or individuals + within the organization assigned the responsibility for receiving reports + of suspected ITAR violations along with their contact information. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + description: Empower employees to speak up if they are unsure about the proper + course of action, if they believe they may have been involved in an activity + that violated the ITAR, or if they believe another employee is violating or + about to violate the ITAR. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + description: Provide assurances that employees will not suffer any negative + consequences for reporting a suspected violation in good faith. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + description: Incorporate ITAR compliance into employee performance plans and + evaluations. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4a:2 + description: "Implement reporting procedures for organizations to voluntarily\ + \ disclose ITAR violations to DDTC and also to mandatorily disclose ITAR violations\ + \ involving proscribed destinations pursuant to ITAR \xA7 126.1(e)(2)." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4 + ref_id: ELEMENT 4B + name: Establish Policies and Procedures for Investigating ITAR Violations and + Implementing Corrective Actions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b + description: 'Organizations should draft, periodically update, and make available + to employees policies and procedures for investigating and addressing potential + ITAR violations that are reported or otherwise detected. These policies and + procedures should cover, among other things, how the organization will:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: Determine when to investigate suspected violations. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: Document the information reported, detected, or otherwise obtained + as part of the investigation. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: Analyze the root causes of any ITAR violations. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: Draft a report describing the outcome of the investigation and + the recommended corrective actions, including any recommended disciplinary + measures. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: Present the report to and brief management. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: "Document management\u2019s response to the report and whether\ + \ management approved the recommended corrective actions." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: Implement the corrective actions and document the implementation + of the corrective actions, including who implemented them and how. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: ' Monitor the corrective actions to ensure they remain fully implemented + and are working properly over time.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1:9 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:1 + description: Report back to management after the approved corrective actions + are implemented. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4b + description: "Organizations should use personnel qualified to conduct timely\ + \ and properly scoped investigations of ITAR violations and should ensure\ + \ that such personnel have adequate resources and funding. Organizations should\ + \ ensure that investigations are independent, objective, thorough, and properly\ + \ documented. Organizations should consult in-house and outside ITAR experts,\ + \ where appropriate, during or after an investigation. Management\u2019s response\ + \ to such investigations should reflect the critical importance of ITAR compliance,\ + \ including by recognizing and rewarding employees who report suspected ITAR\ + \ violations. Organizations should also continuously update their compliance\ + \ programs to incorporate changes to the ITAR and lessons learned from past\ + \ violations." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4 + ref_id: ELEMENT 4C + name: Establish Policies and Procedures for Properly Submitting Voluntary Disclosures + to DDTC + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c + description: "Organizations should develop written policies and procedures for\ + \ disclosing ITAR violations to DDTC. Organization should ensure that these\ + \ policies and procedures are fully consistent with all requirements set forth\ + \ in ITAR \xA7 127.12 for voluntary disclosures." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c + description: "DDTC strongly encourages organizations to disclose suspected ITAR\ + \ violations promptly. DDTC may consider a voluntary disclosure pursuant to\ + \ ITAR \xA7 127.12 as a mitigating factor in determining the administrative\ + \ penalties, if any, that should be imposed. However, for a disclosure to\ + \ be considered \u201Cvoluntary\u201D for purposes of ITAR \xA7 127.12, it\ + \ must be made prior to the time the U.S. Government becomes aware of either\ + \ the same or substantially similar information from another source and initiates\ + \ an investigation or inquiry of its own. Accordingly, an organization that\ + \ wishes to obtain the significant mitigation credit for voluntary disclosures\ + \ should disclose any violations as quickly as possible to DDTC. Failure to\ + \ voluntarily disclose a violation may result in circumstances detrimental\ + \ to U.S. national security and foreign policy interests and will be an adverse\ + \ factor in determining the appropriate disposition of the matter. DDTC reviews\ + \ and closes most voluntary disclosures without any administrative action." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c:3 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c + description: "Organizations should submit an initial notification to DDTC pursuant\ + \ to ITAR \xA7 127.12. If they have not yet identified all the required information\ + \ under ITAR \xA7 127.12, then they may subsequently provide a full disclosure\ + \ within 60 days. Organizations that request extensions for the submission\ + \ of a full disclosure are encouraged to do so as far in advance of the 60-day\ + \ deadline as possible. If organizations confirm that no ITAR violation occurred\ + \ after submitting an initial notification, then they may request a withdrawal\ + \ of their notification." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c:4 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c + description: "Organizations should ensure that voluntary disclosure submissions\ + \ contain all the required information, provide appropriate documentation,\ + \ and enclose the certification required in ITAR \xA7 127.12(e). Consistent\ + \ with these requirements, voluntary disclosures should demonstrate that the\ + \ organization conducted a thorough root cause analysis to determine why ITAR\ + \ violations occurred, including by identifying whether the violations are\ + \ systemic." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c:5 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4c + description: "In the event the organization\u2019s policies and procedures should\ + \ have prevented a violation, the disclosure should identify the business\ + \ units that had ownership of the specific policies and procedures at issue\ + \ and explain how those units have been held accountable. Voluntary disclosures\ + \ should also demonstrate that the organization developed and has either implemented\ + \ or has plans to implement corrective actions that address the root causes\ + \ and prevent the recurrence of similar violations." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4 + ref_id: ELEMENT 4D + name: Communicate Potential Consequences of ITAR Violations to Employees + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d + description: 'Management should ensure that all employees understand their legal + obligations under the AECA and ITAR, as well as consequences for violating + those obligations. Management should make available educational materials + and post visual reminders to all relevant employees that underscore the following:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + description: ITAR controls ensure that commercial exports of defense articles + and defense services advance U.S. national security and foreign policy objectives. + Criminal and civil penalties for violating the ITAR are severe because such + violations may harm U.S. national security and foreign policy. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + description: Criminal convictions for willful ITAR violations can result in + a maximum criminal penalty of $1,000,000 per violation, imprisonment of up + to 20 years per violation, or both. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + description: Organizations and/or individuals criminally convicted of ITAR violations + will also be subject to statutory debarment that renders them ineligible to + participate directly or indirectly in defense trade for a specified period. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + description: Civil penalties for ITAR violations can result in a fine of more + than $1,200,000 per violation, and that amount increases annually to adjust + for inflation. DDTC imposes civil penalties based on strict liability unless + otherwise specified in the text of the ITAR. This means that organizations + and/or individuals may be held civilly liable for ITAR violations even if + they did not know or have reason to know that they were violating the ITAR. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + description: Any ITAR violation, regardless of intent, may trigger administrative + debarment if the violation provides DDTC with a reasonable basis to believe + that the violator cannot be relied upon to comply with the ITAR in the future. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + description: Administrative settlements typically include the execution of a + Consent Agreement under which the respondent is required to institute enhanced + compliance measures for a period of two to four years. Instituting these enhanced + compliance measures is typically time and resource intensive for most organizations. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:1 + description: "Administrative settlements are posted publicly on DDTC\u2019s\ + \ website, which may result in both negative publicity and reputational damage\ + \ for the respondent." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-4d + description: Management should also ensure that employees understand other potential + consequences, including possible disciplinary actions, for ITAR violations + within an organization. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5 + assessable: false + depth: 1 + ref_id: ELEMENT 5 + name: ITAR TRAINING + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5 + ref_id: ELEMENT 5A + name: ITAR Training Programs + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a + name: ITAR Training Programs Basics + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:1 + description: ITAR training programs should be tailored, dynamic, up-to-date, + and adequately resourced. They should also clearly identify the job-specific + export control responsibilities for all employees. Programs should allot sufficient + time for employees to complete their training, and they should offer training + on a recurring basis, at a minimum annually. Organizations should maintain + accurate training records to verify that employees have completed all relevant + compliance-related training sessions. In addition to offering formal ITAR + training sessions on a recurring basis, organizations should make available + ITAR training resources that employees may consult at any time. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a + name: Tailoring ITAR Training Programs + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2 + description: 'Organizations should ensure that ITAR training programs are tailored + to address their specific compliance risks. Some of the risks that organizations + should consider when designing an ITAR training program include the following + and discussed in detail in Element 6 of this document:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1 + description: The nature and scope of their defense articles and defense services + being provided; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1 + description: The parent, subsidiaries, affiliates, suppliers, customers, clients, + business partners and other relevant parties with which they interact, directly + or indirectly; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1 + description: The geographic regions in which they operate; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:2:1 + description: The duties and responsibilities of the employees and other personnel + being trained. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a + name: Implementing Dynamic and Up-to-Date ITAR Training Programs + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:3 + description: "ITAR training programs should be dynamic and reviewed periodically\ + \ for updates and revisions based on changes in the organization\u2019s commodities\ + \ and their end uses and end users, as well as any changes to the ITAR or\ + \ guidance from DDTC. Organizations should monitor the Federal Register and\ + \ DDTC\u2019s website routinely for ITAR-related updates that should be integrated\ + \ into recurring training sessions. Organizations should also establish a\ + \ mechanism to disseminate ITAR-related updates to personnel in a timely manner\ + \ in between training sessions, such as through organization-wide email updates" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:3:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:3 + description: "Organizations should also stay informed of export compliance best\ + \ practices and monitor relevant publications that may describe export compliance\ + \ enhancements and lessons learned from export control violations by other\ + \ organizations. For instance, upon learning of an ITAR violation or \u201C\ + close call\u201D within one\u2019s own organization, or identifying vulnerabilities\ + \ in the organization\u2019s ICP, or obtaining a negative testing result or\ + \ audit finding, organizations should use such incidents to provide specific\ + \ training to relevant personnel within the organization, in addition to taking\ + \ corrective action." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a + name: Hiring Knowledgeable and Experienced Trainers + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5a:4 + description: An effective ITAR training program requires knowledgeable, experienced + trainers. Organizations should ensure their trainers are subject matter experts + on the ITAR who keep well-informed regarding the latest changes to the ITAR, + guidance from DDTC, and industry best practices. Internal trainers should + pursue their own continuing education to ensure that they remain subject matter + experts in the field. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5 + ref_id: ELEMENT 5B + name: "Tiered Training Based on Each Employee\u2019s Functions" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b + description: "Organizations should adopt a tiered ITAR training program based\ + \ on the responsibilities of each employee and other personnel within the\ + \ organization. Organizations should tailor their ITAR programs as specifically\ + \ as possible to help employees and other personnel understand their specific\ + \ export control responsibilities in light of the organization\u2019s risk\ + \ profile. Organizations should provide their employees and other personnel\ + \ with different levels and types of ITAR training depending on the knowledge\ + \ and skills needed to perform their job functions and the compliance risks\ + \ that arise in each position. For example, training programs could be divided\ + \ into four tiers, directed at four categories of positions within the organization,\ + \ as reflected in the pyramid diagram above and described below. Smaller organizations\ + \ may adopt this tiered approach or provide comprehensive ITAR training to\ + \ all personnel." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b + ref_id: Tier 1 + name: General ITAR Training for All Personnel + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1 + description: "For the first and bottom tier \u2013 all personnel \u2013 training\ + \ should cover the basics of export controls and should be comprehensible\ + \ for a broad audience with little or no background in export controls or\ + \ the ITAR. Generally, this level of training is provided to all personnel\ + \ within organizations. Organizations should provide the training to all new\ + \ hires and contractors during the onboarding process and then reinforce that\ + \ training through periodic education and awareness activities to those with\ + \ little or no exposure to exports." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1 + description: "Tier 1 training should provide all personnel within the organization\ + \ a basic understanding of the ITAR and a clear understanding of everyone\u2019\ + s shared export compliance responsibilities within the organization. Tier\ + \ 1 training should, at a minimum, cover the following topics:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: 'Basic ITAR overview, including:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1:1 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1 + description: Regulated activities; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1:2 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1 + description: Key ITAR definitions, including export, foreign person, technical + data, defense service, and defense article, and provide real world examples + specific to the organization's business; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1:3 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1 + description: Licenses or other approvals; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1:4 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:1 + description: How ITAR violations occur. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: "Overview of the organization\u2019s ICP" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: Recordkeeping procedures + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: "Red flags specific to the organization\u2019s business" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: Screening requirements + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: Practical advice and case studies to address real-life scenarios + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: Company-specific risk profile and high-risk compliance areas + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: Reporting ITAR violations + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: 'Potential consequences of violating the ITAR:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9:1 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9 + description: Strict liability for civil violations; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9:2 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9 + description: Civil and/or criminal monetary penalties; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9:3 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9 + description: Imprisonment for criminal violations; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9:4 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:9 + description: Debarment + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:10 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: Enhancing ITAR-compliance processes + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2:11 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-1:2 + description: Organization charts and contact information for key export compliance + personnel, Empowered Officials, and other relevant personnel. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b + ref_id: Tier 2 + name: Senior Management + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2 + description: "For the second tier \u2013 senior management \u2013 training should\ + \ be more detailed and include more than just the basics of export controls.\ + \ Senior management must have a thorough understanding of export controls\ + \ to properly comprehend the compliance risks associated with the organization\u2019\ + s activities and risk profile. Organizations with a Board of Directors or\ + \ a Board of Trustees should conduct the same type of top-level briefing for\ + \ them as well." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2 + description: 'Tier 2 training should provide senior management with an intermediate + level of understanding of the ITAR and a clear understanding of the critical + role senior management plays in ITAR compliance within the organization. In + addition to topics covered in Tier 1, Tier 2 training should, at minimum, + include an intermediate ITAR overview and the following topics:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2 + description: "Detailed description of the organization\u2019s ICP;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2 + description: The importance of communicating management commitment to complying + with U.S. export controls; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2 + description: Allocating appropriate resources and hiring adequate staff to ensure + ITAR compliance; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2 + description: Creating and maintaining a culture of ITAR compliance within the + organization; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-2:2 + description: A detailed description of the potential consequences of violating + the ITAR. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b + ref_id: Tier 3 + name: Positions with Export Functions + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3 + description: "The specific personnel that fall in the third tier \u2013 positions\ + \ with export functions \u2013 will vary from one organization to another,\ + \ depending on the organization\u2019s activities. For most companies, it\ + \ will likely include program management, technical, and/or engineering personnel\ + \ with access to ITAR-controlled defense articles, shipping and receiving,\ + \ supply chain, business development, human resources, and IT." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:2 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3 + description: For universities, it will likely include administrative staff, + researchers, faculty and/or principal investigators involved in activities, + including, e.g., contracts and grants, product development, and research labs, + as well visiting foreign students and scholars participating in controlled + research. Organizations should provide more detailed and targeted ITAR training + to such personnel, at a minimum, on an annual basis. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3 + description: 'Tier 3 training should provide relevant employees with export + functions with an advanced- level understanding of the ITAR and their significant + export compliance responsibilities within the organization. In addition to + topics covered in Tiers 1 and 2, as appropriate, Tier 3 training should, at + minimum, cover the following additional topics:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: How to handle technical data, including marking procedures; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Deemed exports; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Jurisdiction and classification; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Pertinent USML Categories; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Export authorization approval process; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: License conditions and exceptions; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Exemptions applicable to business; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Agreement and license types; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Non-Disclosure Agreements; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:10 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Recordkeeping; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3:11 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-3:3 + description: Targeted training to individual roles. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b + ref_id: Tier 4 + name: Export Compliance Team + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4 + description: "The final and top tier of the training program comprises the export\ + \ compliance team, including the EO, export compliance manager, compliance\ + \ supporting staff, and legal counsel advising on export compliance issues.\ + \ Training for this group should be thorough and detailed and include not\ + \ only the organization\u2019s ICP but training on all export control regulations\ + \ that could impact the organization\u2019s exporting activities." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4 + description: Compliance managers and their team also need to receive training + on potential future needs for their organization, including mergers, acquisitions, + or divestitures, development of a new product line, expansion into a new region + of the globe, or new developments in U.S. foreign policy. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4 + description: 'Tier 4 training should provide the export compliance team with + an expert-level understanding of the ITAR and their export compliance responsibilities + within the organization. In addition to topics covered in Tiers 1, 2, and + 3, as appropriate, Tier 4 training should, at minimum, cover the following + additional topics:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3 + description: Establishing and maintaining ITAR policies and procedures, including + the ICP. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3 + description: "Obtaining and tracking the use of the organization\u2019s licenses\ + \ and other approvals." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3 + description: Establishing TCPs. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3 + description: 'Other detailed training in specific areas of export regulations + relevant to the organization, such as:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4:1 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4 + description: Export document preparation, + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4:2 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4 + description: Country-specific diversion risks, + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4:3 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4 + description: Recordkeeping requirements, and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4:4 + assessable: true + depth: 6 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:4 + description: Self-assessments and internal audits. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:tier-4:3 + description: Attending DDTC seminars and other outside training programs as + appropriate. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b + name: Employee Accountability + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-5b:2 + description: Organizations should include ITAR training as a requirement in + performance plans and reviews and ensure that employees and other personnel + complete their ITAR training on time. Organizations should also hold employees + and other personnel accountable for both completing their ITAR training in + a timely manner and for completing refresher training to retain their knowledge + from their initial training. Further, at the end of each ITAR training session, + organizations should test employees on the materials and issue a certificate + of completion when they successfully complete the test. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6 + assessable: false + depth: 1 + ref_id: ELEMENT 6 + name: RISK ASSESSMENT + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6 + ref_id: ELEMENT 6A + name: ITAR Risk Assessments + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a + name: Basics of ITAR Risk Assessments + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:1 + description: Risk assessments are essential tools for building an effective + ICP. Risk assessments in the defense trade controls context are evaluations + of the potential compliance risks that are specific to each organization and + that, if left unaddressed, may lead to ITAR violations. Risk assessments therefore + allow organizations to ascertain and analyze the likelihood that ITAR violations + may occur, the most common reasons violations may occur, and the types of + violations that are most likely to occur or would result in the greatest harm. + After understanding the full spectrum of their compliance risks, organizations + should use that data to create effective and tailored ICPs and allocate resources + as appropriate to prioritize and mitigate those risks. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a + name: Tailoring ITAR Risk Assessments + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2 + description: "Risk assessments should be tailored to the organization\u2019\ + s ITAR-controlled activities and should identify and analyze all the potential\ + \ ITAR-related risk factors for the organization, whether those risk arise\ + \ inside or outside of the organization. Such potential risk factors may include\ + \ the following:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + description: "Nature and scope of the organization\u2019s commodities;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + description: "Organization\u2019s customers, suppliers, freight forwarders,\ + \ partners, or other third parties involved in its activities;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + description: "Organization\u2019s physical and cyber security infrastructure;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + description: Any foreign parents, subsidiaries, or affiliates; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + description: " Structure of the organization\u2019s product development, engineering,\ + \ and sales activities;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + description: Any foreign person employees; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:2:1 + description: Geographic regions that the organization operates in or exports + to. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a + name: Development of ITAR Risk Assessments + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:3 + description: "Organizations should develop a risk-assessment to identify, assess,\ + \ and track risks associated with ITAR compliance. Organizations should regularly\ + \ update their ITAR risk assessments to account for changes to their risk\ + \ factors. For example, if an organization begins exporting to a new geographic\ + \ area or opens a new foreign office, the organization should update its risk\ + \ assessment accordingly. Updating the risk assessment is also important following\ + \ mergers, acquisitions, and divestitures, particularly if the company merges\ + \ or acquires foreign persons. In addition, organizations should update their\ + \ risk assessment if they discover new or evolving ITAR compliance risks through\ + \ audit findings, ITAR violations or \u201Cclose calls,\u201D employee feedback,\ + \ or any other sources." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:3:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:3 + description: Organizations may internally design, update, and conduct the ITAR + risk assessment, or they may retain outside ITAR experts to do so. Organizations + should ensure that their original risk assessments and any updates, as well + as any changes to ICPs because of their risk assessments, are fully documented + and preserved. DDTC recommends examining the Sample Audit Checklists in Element + 7 to help assess and determine possible risk factors. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a + name: Frequency of ITAR Risk Assessments + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:4 + description: Organization should periodically review risk assessments to determine + whether its risks are properly addressed. Periodic risk assessments will depend + on specific circumstances and how quickly risks change. There is no one-size-fits-all + approach for updating risk assessments, but organizations should ensure that + the frequency is adequate to accurately account for the potential ITAR compliance + risks at any given time. For example, the organization may decide to conduct + a company-wide risk assessment every year or perform targeted risk assessments + focused on certain risk areas on an ad-hoc basis throughout the year. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a + name: Prioritizing and Mitigating ITAR Compliance Risks + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:5:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6a:5 + description: After performing their ITAR risk assessments, organizations should + analyze and prioritize those risks based on all relevant factors, including + the likelihood that such risks would result in ITAR violations. Organizations + should then integrate their risk-based analysis and prioritization into their + ICPs and allocate resources as appropriate to mitigate those risks. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6 + ref_id: ELEMENT 6B + name: Addressing Common ITAR Risk Areas + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b + description: 'This section identifies some common risk areas for purposes of + conducting ITAR risk assessments and developing and updating ICPs. As described + above, ITAR compliance risks may vary across organizations. Organizations + have frequently identified risks in the following areas:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: 'Jurisdiction and Classification: ITAR violations frequently result + from the incorrect jurisdiction and classification of defense articles and + defense services.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: 'Authorization Management: ITAR violations frequently result from + failing to adhere to the terms and conditions of licenses and agreements.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: 'Foreign Person Employees or Visitors: foreign person employees, + visitors, etc. may pose a compliance risk to organizations if they are not + properly authorized to have access to defense articles, including technical + data, or receive defense services. ITAR violations frequently result from + companies that allow foreign person employees to access technical data stored + on internal company networks without first obtaining a license.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: "Vetting of Parties and Verification of End Users: customers and\ + \ other parties to a transaction present a compliance risk for exporters.\ + \ It is the exporter\u2019s responsibility to vet customers and other parties\ + \ to a transaction. ITAR violations regularly occur when organizations fail\ + \ to perform sufficient due diligence and defense articles are used in a manner\ + \ that is inconsistent with the DDTC authorization." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: "License Exemptions: the ITAR contains various license exemptions\ + \ that do not require a request for approval from DDTC. ITAR violations routinely\ + \ result from failing to meet and document each exemption\u2019s requirements." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: "International Travel: employees that travel internationally with\ + \ organization-issued hardware or software and employees that can access their\ + \ employer\u2019s networks and databases while overseas may present a substantial\ + \ compliance risk, particularly if ITAR-controlled technical data is saved\ + \ on portable devices or if it is accessible or downloadable without adequate\ + \ IT security measures. Employees may provide defense services during trade\ + \ shows, business development, or training/maintenance on defense articles." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: 'Facility Visits: failing to verify the U.S.-person status of all + visitors in advance of plant tours or facility visits in the U.S. creates + the risk of inadvertent release of ITAR-controlled technical data. Organizations + may seek a license or other approval from DDTC, as appropriate, in advance + of foreign person visits. For facility visits at non-U.S. subsidiaries, failing + to verify citizenship and the organization they represent against the license + or other approval.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:1 + description: 'Inventory Management: Inventory management and tracking of ITAR- + controlled items can also present compliance risks. ITAR violations may result + from organizations not adequately securing their inventory of defense articles + and not tracking them appropriately once exported.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-6b + description: See DDTC's website for the DDTC ITAR Risk Matrix, and supplementing + University- specific Risk Matrix, that outline important areas of risk to + consider when analyzing an ITAR compliance program. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7 + assessable: false + depth: 1 + ref_id: ELEMENT 7 + name: AUDITS & COMPLIANCE MONITORING + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7 + ref_id: ELEMENT 7A + name: Audits + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a + description: Comprehensive, independent, and objective audits, performed regularly, + assist organizations in determining the effectiveness of their ICP. Such audits + allow organizations to identify deficiencies in their ICP and remediate them. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a + name: Audit Personnel + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2 + description: 'Organizations should assemble an internal team or, as appropriate, + hire external third parties to conduct periodic ITAR compliance audits. If + the organization already has an auditing team, it should incorporate ITAR + policies and procedures with corporate audits. Auditors, whether internal + or external, should determine the appropriate type and scope of the audit. + Organizations should ensure their auditors have sufficient:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1 + description: Qualifications, technical knowledge, strong ITAR expertise, and + sufficient resources to conduct the audit; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1 + description: Authority to ensure employees comply with audit-related requests + for information; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1 + description: Independence from the audited activities; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:2:1 + description: "Autonomy and independence from management, including direct access\ + \ to any relevant employees, the board of directors, and/or the board\u2019\ + s audit committee." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a + name: Audit Methodology + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3 + description: 'Audits should consist of:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1 + description: Interviews with relevant functional area personnel, as well as + the compliance team and senior management, as appropriate; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1 + description: Document collection and review; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1 + description: Access to IT systems; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:1 + description: Site visits, as appropriate. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:3 + description: "Auditors should maintain a detailed log to track the progress\ + \ of documents requested and obtained, interviews requested and completed,\ + \ and sites visited. The auditors should coordinate all interviews with the\ + \ organization\u2019s compliance department, as appropriate. The audit team\ + \ should review all documents provided by the relevant business units in the\ + \ development of checklists to be used when conducting the interviews and\ + \ site visits. See Section C below for examples of such checklists." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a + name: Types of Audits + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4:1 + assessable: false + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4 + description: Different types of audits serve different purposes, and organizations + should develop, as appropriate, an audit strategy, utilizing the different + types of audits listed below, that is right for their circumstances. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4:1:1 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4:1 + description: 'Functional-Level Audits: functional-level audits look at distinct + areas of compliance programs, e.g., recordkeeping or shipping procedures. + This audit type can help identify risk areas at an early stage and provide + an opportunity to correct any deficiencies. Functional-level audits should + be conducted more frequently than program-level audits because they are smaller + in scale.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4:1:2 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4:1 + description: 'Program-Level Audits: at the program-level, organizations should + conduct internal audits as periodically as appropriate. Program-level audits + should include both a review of all export policies and procedures and an + assessment of whether each business unit implemented such policies and procedures.' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4:1:3 + assessable: false + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:4:1 + description: "External Audits: external audits can provide an unbiased, third-party\ + \ evaluation of an organization\u2019s overall compliance program and practices.\ + \ Organizations should consider the use of an outside auditor periodically,\ + \ as appropriate." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a + name: Audits in the Context of Mergers, Acquisitions, and Divestitures + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5 + description: Audits may be appropriate when mergers, acquisitions, and divestitures + (MAD) occur. Pursuant to ITAR part 122, DDTC registrants must notify DDTC + within specific timeframes regarding certain changes in registration, including + ownership and legal organizational structure. Many of these notice requirements + arise during the pre- and post-closing processes of MAD transactions. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5 + description: "Acquiring organizations should conduct due diligence reviews of\ + \ target organizations that engage in ITAR-controlled activities. Due diligence\ + \ reviews should assess the effectiveness of the target organization\u2019\ + s ITAR compliance program and identify potential past ITAR violations. In\ + \ the event such ITAR violations have not already been reported to DDTC, the\ + \ target organization or the acquiring organization are strongly encouraged\ + \ to submit a voluntary disclosure prior to or immediately after closing,\ + \ as appropriate." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5 + description: The acquiring organization should conduct an audit after closing + the merger, acquisition, or divestiture. The appropriate scope of any post-closing + audit will vary depending upon the circumstances. If the acquiring organization + uncovers numerous unresolved compliance issues in its pre- closing due diligence, + an in- depth audit may be appropriate. If, on the other hand, the target organization + had a robust compliance program and provided documentation of regular audits + and remedial actions, the acquiring organization may choose to perform a functional + audit instead. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:5 + description: "Acquiring organizations should ensure that any continuing ITAR\ + \ violations by the acquired organization identified through the post-acquisition\ + \ audit are stopped and remediated. Organizations should follow the relevant\ + \ procedures in ITAR \xA7 127.12 to investigate and voluntarily disclose the\ + \ violations to DDTC." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:6 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a + name: Sharing Audit Findings and Following Up + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:6:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:6 + description: After the auditors complete their interviews, document collection + and review, and site visits, they should write a draft audit report. The draft + audit report should include an executive summary, findings and recommendations, + and appendices that explain the methodology, including the interviews conducted, + documents reviewed, and sites visited. Prior to finalizing the audit report, + the auditors should share their findings and recommendations with the relevant + business units to correct any inaccuracies. After making any final modifications, + auditors should brief senior management on the audit findings and recommendations. + Organizations should ensure the final audit report is provided to all relevant + business units, as well as senior management. Organizations should maintain + audit reports for at least five years. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:6:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:6 + description: If an audit report includes recommendations for revisions to procedures + or corrective actions, organizations should include specific timetables and + an implementation plan for management to approve. Organizations should continue + to track the progress of corrective actions until they are completed. Once + corrective actions are completed, organizations should prepare an additional + report to management, and compliance personnel should confirm that each corrective + action has been fully implemented. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:6:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7a:6 + description: Each vulnerability or violation identified in an audit is an opportunity + for organizations to improve their ICP. Organizations should incorporate these + lessons learned into training programs and their ICP in order to share them + across business units and functions. Organizations should also actively plan + to remediate deficiencies in their ICPs that audit findings identify. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7 + ref_id: ELEMENT 7B + name: Compliance Monitoring + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b + description: 'In addition to conducting periodic audits, organizations should + regularly review their ICPs and amend their ITAR compliance policies and procedures + as appropriate in response to:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1 + description: Any changes to the ITAR or DDTC guidance; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1 + description: Export compliance best practices and lessons learned from export + control violations by other organizations; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1 + description: "Lessons learned from any ITAR violations or \u201Cclose calls\u201D\ + \ within the organization;" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1 + description: "Vulnerabilities identified in the organization\u2019s ICP, or\ + \ negative testing results or audit findings; and/or" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7b:1 + description: "Changes to an organization\u2019s ITAR risk factors, including\ + \ where such risk factors have changed because of a merger, acquisition, and/or\ + \ divestiture, or where there are changes to the organization\u2019s product\ + \ line, services, or customers." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7 + ref_id: ELEMENT 7C + name: Sample Audit Checklists + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + description: "The following are sample checklists that auditors should further\ + \ develop before conducting an audit. Auditors should use these sample checklists\ + \ to formulate document requests and interview questions for employees within\ + \ the relevant functional areas of organizations. These sample checklists\ + \ are not intended to be exhaustive, and they may not all be applicable to\ + \ every organization. Auditors should customize checklists based on relevant\ + \ factors, including an organization\u2019s specific activities and risk profile." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Management + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: &id001 + - 'Yes' + - 'No' + - Alternate + - N/A + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:question:1 + text: "Has senior management issued a formal statement clearly communicating\ + \ your organization\u2019s commitment to compliance with U.S. export control\ + \ laws and regulations?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:1:question:1 + text: "Does this statement include contact information for the person and\ + \ Empowered Official primarily responsible for your organization\u2019\ + s export compliance?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:2:question:1 + text: Is this statement easily accessible online or in print? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:3:question:1 + text: Has this statement been distributed to all employees whose work is + impacted by export regulations? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:4:question:1 + text: "Are employees whose work is impacted by export regulations required\ + \ to sign an acknowledgment that they understand the organization\u2019\ + s obligation to comply with U.S. export laws and its commitment to compliance?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:5:question:1 + text: Does your management assess ITAR compliance resource needs at least + on an annual basis? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:1:6:question:1 + text: Has senior management communicated its commitment to compliance directly + to those in leadership/authority positions, particularly business leads + over the areas of the organization where export-controlled work is performed? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2:question:1 + text: Has your organization drafted, implemented, and disseminated written + policies and procedures regarding export trade compliance? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2:1:question:1 + text: Are these policies and procedures widely disseminated and readily + accessible throughout your organization? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2:2:question:1 + text: Does your organization ensure that the policies and procedures are + followed? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:2:3:question:1 + text: Does your organization make available to all employees an organizational + chart that clearly identifies personnel with authority over export control + matters? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:question:1 + text: " How does the trade compliance office support your organization\u2019\ + s different divisions in general and management in particular?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:1:question:1 + text: How many trade compliance personnel do you have on staff? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:2:question:1 + text: Do you believe the trade compliance function is adequately staffed + to support your organization? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:3:question:1 + text: To whom does the trade compliance function report? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:4:question:1 + text: Do trade compliance personnel participate in staff meetings? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:2:3:5:question:1 + text: Are trade compliance staff integrated into business development decisions? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Trade Compliance + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:1:question:1 + text: Does the trade compliance function have sufficient support from management? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:2:question:1 + text: Is trade compliance your primary area of responsibility? Do you have + any other responsibilities within your organization? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:2:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:2:1:question:1 + text: Who is your backup when you are out of the office? Is that person + properly trained, and do they have the authority to act on your behalf? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3:question:1 + text: Does your organization provide tailored training for different functional + areas, e.g., program management, business development, contracts, procurement, + etc.? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3:1:question:1 + text: How often and what type of training do trade control personnel receive + annually? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:3:2:question:1 + text: Who is responsible for export control training? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4:question:1 + text: Does the trade compliance office routinely conduct risk assessments + for the organization? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4:1:question:1 + text: Have you determined areas of your organization that currently perform + or are likely to perform ITAR-related activities? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:4:2:question:1 + text: Have you identified and implemented measures to address risk areas? + If so, have you conducted an inventory of these areas to confirm whether + they currently contain or are likely to receive or develop any defense + articles, defense services or technical data? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:5:question:1 + text: How does your organization classify its commodities? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:6:question:1 + text: Does your organization maintain a product/technology matrix with USML + categories? If so, how and by whom is the matrix maintained and updated? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:question:1 + text: What processes are in place for reporting potential ITAR violations? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:1:question:1 + text: "Does a \u201Chotline\u201D within the organization exist where employees\ + \ can report potential violations, including anonymously?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:2:question:1 + text: Does management support investigations into potential violations? + Is there support from management to hold personnel responsible for violations? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:3:question:1 + text: Who is responsible for investigating potential violations? If outside + counsel is involved, is the Empowered Official also involved in the review + and findings? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:4:question:1 + text: What process is used to ensure corrective actions, if any, are put + in place and verified? Who is responsible for this action? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:7:5:question:1 + text: Does the Empowered Official have the authority and backing from management + to stop any actions that may lead to a violation? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:question:1 + text: Do you have a system/process in place to assess, review, and identify + areas where a license, exemption, or other approval will be required? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:1:question:1 + text: What is the volume of licensing activity in each business unit? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:2:question:1 + text: Who determines whether a license is needed from DDTC? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:3:question:1 + text: Who is responsible for submitting export license requests to the DDTC? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:4:question:1 + text: How is party screening performed and who is responsible for this process? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:5:question:1 + text: What are the procedures for responding to negative/positive screening + responses? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:6:question:1 + text: "When a license or other approval is received, explain the process\ + \ for implementing the authorization within your organization\u2019s divisions,\ + \ e.g., how do you ensure that licenses are properly decremented and that\ + \ temporary exports are returned? Who is responsible for meeting any conditions\ + \ of approvals?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:7:question:1 + text: Explain how you track licenses, agreements, and other approvals to + ensure you properly close them out, seek a replacement, or request an + extension for an authorization. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:8:question:1 + text: How do you track the release of technical data via telephone, fax, + email, hand carry or other means? How do you document these releases to + authorized foreign person employees? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:9 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:9:question:1 + text: "How often does the organization\u2019s trade compliance office perform\ + \ audits on licenses and other authorizations? What percentage (random,\ + \ 5-10%, 50%, or 100%) is used when conducting such audits? Where are\ + \ the results of the audits stored?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:10 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:10:question:1 + text: Do policies and procedures exist regarding the recordkeeping and reporting + requirements under the ITAR and are those policies and procedures readily + available to employees? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:11 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:8:11:question:1 + text: "Who ensures that employees are complying with ITAR recordkeeping\ + \ and reporting requirements, as well as whether personnel are complying\ + \ with our organization\u2019s policies and procedures?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:question:1 + text: Does your organization verify that suppliers are able to properly + handle ITAR-controlled defense articles and defense services, including + technical data? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:1:question:1 + text: Do your suppliers employ foreign persons? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:2:question:1 + text: "Do your suppliers always provide an export classification of the\ + \ parts being procured? If not, the organization may want to obtain the\ + \ proper classification of suppliers\u2019 parts." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:3:question:1 + text: Do you have a supplier due diligence process? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:4:question:1 + text: If you provide ITAR-controlled technical data to suppliers, do you + consistently identify defense articles, including technical data, as such? + Do you include markings on the technical data itself and on packing materials, + emails, etc.? Do you ensure that suppliers understand their obligations + under the ITAR not to export, reexport, or retransfer that technical data + without first obtaining DDTC approval? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:9:5:question:1 + text: Do your terms and conditions include trade controls related requirements + such as compliance with the ITAR? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:10 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:10:question:1 + text: Are trade compliance personnel invited to business development meetings + so that they can properly anticipate and prepare for business pursuits + that may require authorizations from DDTC in the future? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:11 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:11:question:1 + text: Are engineering or business development personnel aware that a license + is needed to export technical data or provide defense services to foreign + customers? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:11:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:11 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:11:1:question:1 + text: If not, what level of training is provided to business development + personnel prior to meeting with a foreign customer. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:question:1 + text: Are trade compliance personnel aware of meetings with foreign customers + concerning ITAR-controlled programs? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:1:question:1 + text: What is the process for approving any international travel? Are trade + compliance personnel aware of all such travel? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:2:question:1 + text: Is export compliance training provided prior to any international + travel? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:3:question:1 + text: Does your organization have a mobile device (laptop and hand- held + devices) policy? Are employees trained on the appropriate use of such + devices when traveling abroad? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:3:12:4:question:1 + text: What policy is in place to address hand-carry of defense articles + outside of the U.S.? Who is responsible for overseeing this process and + what measures are in place to control this type of export? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Program Management / Principal Investigators + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:1:question:1 + text: What training have you received regarding export compliance, and how + often is it repeated? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:1:1:question:1 + text: Do you know whom to contact if you have any questions regarding export + compliance? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:2:question:1 + text: What procedures exist for approving international travel? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:3:question:1 + text: What procedures exist for safeguarding technical data or other proprietary + information on mobile devices while traveling internationally? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:4:question:1 + text: What procedures exist for approving what information may be shared + during meetings with foreign nationals, regardless of the location, domestic + or internally? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:5:question:1 + text: How do you comply with the terms of any export license or other approvals? + Who is ultimately responsible for managing authorizations? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:6:question:1 + text: How do you coordinate with the shipping and receiving department regarding + exports and temporary imports of ITAR-controlled defense articles? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:7:question:1 + text: What is the process for repair and return of parts? How is this coordinated + with the various functional areas of the business unit and customers? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:8:question:1 + text: Does your organization have a system to capture and track all exports, + including technical data under licenses or other approvals? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:8:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:8:1:question:1 + text: How is this coordinated with the trade compliance team? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:9 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:9:question:1 + text: What is the process for determining when a license is required? If + doubts exist, who do you contact? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:10 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:10:question:1 + text: Is the trade compliance office available to assist and provide you + and your office with timely and sound advice? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:11 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:4:11:question:1 + text: What is the process for hosting foreign persons to your facility. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Human Resources + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:question:1 + text: "What is your organization\u2019s process for hiring a foreign person?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:1:question:1 + text: When an internal request is made to hire a foreign person, does human + resources (HR) verify whether that person will have access to controlled + data or any manufacturing processes? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:2:question:1 + text: Does HR screen potential applicants before they hired? How do they + screen? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:3:question:1 + text: Once a potential foreign person hire is screened, does HR share the + results with the office over trade compliance before extending an employment + offer? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:4:question:1 + text: Is proof of the U.S.-person status verified at the time of hiring? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:5:question:1 + text: How are foreign person employees identified within your organization + (special badge, IT, etc.)? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:6:question:1 + text: Are foreign person employees required to sign non-disclosure agreements? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:7:question:1 + text: Does your organization hire from third-party vendors, e.g., a temp + agency? If so, how are nationalities of the persons hired confirmed? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:8 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:1:8:question:1 + text: Does your organization hire contractors that employ foreign persons? + If so, how is that process conducted and coordinated? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2:question:1 + text: If foreign persons are hired, how does HR coordinate the hiring with + the trade compliance office? When is the process started? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2:1:question:1 + text: "Does the trade compliance office include HR in the export compliance\ + \ training module, and, if so, how is HR\u2019s role characterized?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2:2:question:1 + text: Is there a process in place between HR and the trade compliance office + and/or program management for obtaining a license or other authorization + and, if needed, any renewals necessary for the continued employment of + a foreign person employee? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:2:3:question:1 + text: If a foreign person is relocated to another location/program within + your organization, how is HR/trade compliance office notified? What are + the procedures for handling the transfer process? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:5:3:question:1 + text: If a foreign person employee is terminated, does HR coordinate with + trade compliance office, and, if so, in what manner? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Business Development / Sales + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:question:1 + text: In general, how does Business Development (BD) handle potential opportunities + outside the United States, and how does BD coordinate with the trade compliance + office? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:1:question:1 + text: "Does BD receive tailored export control training? Who is BD\u2019\ + s POC within the trade compliance office?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:2:question:1 + text: "For international proposals, how would you assess BD\u2019s knowledge\ + \ and training regarding whether export authorization is necessary?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:3:question:1 + text: At what point is the trade compliance office consulted and brought + into the process when dealing in international opportunities or proposals? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:4:question:1 + text: Is the trade compliance office consulted in the early stages of internal + opportunities? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:5:question:1 + text: What procedures exist to screen potential business opportunities (parties)? + How do you coordinate screening with the trade compliance office? If you + obtain a negative result, who makes the final call? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:6:question:1 + text: Does your organization use any international consultants? If so, how + is this coordinated and controlled? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:7 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:1:7:question:1 + text: What processes exist for determining whether any BD activity requires + reporting of fees or commissions pursuant to ITAR part 130, and who is + responsible for filing those reports? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:question:1 + text: What is the process for attending a general trade show? How does BD + coordinate with the trade compliance office for trade shows? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:1:question:1 + text: Does BD think of the trade compliance office as a partner in planning + for participation in trade shows? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:2:question:1 + text: Does export compliance provide accurate and timely guidance to BD + in advance of trade shows? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:3:question:1 + text: ' If controlled technical data or a mockup or model are used at a + trade show, how does BD coordinate the licensing requirements with the + trade compliance office?' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:4:question:1 + text: Who is responsible for protecting and securing defense articles at + trade shows? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:5:question:1 + text: Is there a process for determining what is considered public domain + information that may be used at trade shows? Who and how is that determination + made? Is such material appropriately marked? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:2:6:question:1 + text: Is BD aware of and does it understand how to obtain authorization + to designate controlled data into the public domain? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:3:question:1 + text: If operating under a license, how is the license is implemented and + how are its conditions of approval met? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:4:question:1 + text: What is the policy for BD personnel traveling overseas with mobile + devices? Please explain how this is coordinated with IT and the trade + compliance office. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:5:question:1 + text: Does your organization permit hand-carry exports to occur? If so, + please explain the procedures. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:6:question:1 + text: ' How are meetings with foreign persons recorded? What is the procedure + for conducting such meetings?' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:question:1 + text: How does your organization handle a visit by a foreign person? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:1:question:1 + text: Does your organization have an established procedure to conduct a + plant tour? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:2:question:1 + text: Does trade compliance review and approve foreign person visitors in + advance, e.g., are your foreign person visitors screened against restricted/denied + party lists before they visit? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:3:question:1 + text: Are foreign person visitors always escorted by a U.S. person employee + of your organization? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:6:7:4:question:1 + text: While visiting your organization, do visitors always wear badges that + clearly indicate they are non-U.S. Persons? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Engineering / Product Development / Technical Roles + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:1:question:1 + text: How are products or technologies developed? Is it a global or multiparty + process? Are the parties you work with screened prior to collaboration? + If so, who conducts the screening and where are the records kept? If not, + why not? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:2:question:1 + text: What are the procedures used to develop and distribute product or + technology export classifications? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:3:question:1 + text: Are relevant employees trained on processes of jurisdiction and classification, + including the order of review? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:4:question:1 + text: What are the procedures for controlling visitors to access facilities, + especially foreign nationals if involved in the process? Visitor access + to company computer systems? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:5:question:1 + text: Are there formal procedures for the release of sensitive data to third + parties? Is there a mechanism in place to notify and bind recipients of + such data to follow company policy and export control laws? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:6:question:1 + text: "Who is responsible for assessing a commodity\u2019s end use or application?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:7:question:1 + text: With whom in the company is end-use or application specific evaluations/determinations + shared? Does that include trade compliance personnel for purposes of export + classification? Where in the development process is export compliance + consulted? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:7:8:question:1 + text: "Where is product or technology development information stored? In\ + \ hard copy, on site? In hard copy, with the third parties? Electronically\ + \ \u2013 e.g., File Transfer Protocol? Cloud-band? Closed system (i.e.,\ + \ non- networked electronic library)? Other?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Commodity Jurisdiction Process/Classification of Products + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:1:question:1 + text: Is there a process for determining what data is considered general + marketing or public domain information versus technical data that requires + a license or the use of an exemption? What is the process for reviewing + whether the data is in the public domain? Do you clearly identify on the + information itself the ITAR-controlled status of the information? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:2:question:1 + text: Have you developed a standard operating procedure for classification + and designated trained individuals to conduct classification? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:3:question:1 + text: Is a classification review conducted by the Empowered Official in + the compliance office? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:4:question:1 + text: Are procedures in place for ensuring that no technical data is exported + to potential foreign customers or suppliers prior to a review by the trade + compliance office to determine the proper jurisdiction and classification + and any licensing requirements? If so, is there a process for ensuring + that all functional areas (i.e., sales, marketing, business development, + procurement, and program management, etc.) are aware and properly trained + to those requirements? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5:question:1 + text: 'If the company purchases or obtains controlled products or technology, + does it:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5:1:question:1 + text: Determine the proper jurisdiction of the article from the original + equipment manufacturer? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5:2:question:1 + text: If required, implement a technology control plan for the products + or technology obtained? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:8:5:3:question:1 + text: Maintain records of export activities concerning the product(s)? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Shipping + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:1:question:1 + text: Explain in general the process for handling international shipment + of goods. How is this coordinated with trade compliance? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:2:question:1 + text: Does shipping coordinate sufficiently with the trade compliance office? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:3:question:1 + text: Does shipping and receiving receive adequate support and tailored + training from the trade compliance office? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:4:question:1 + text: Who is responsible for obtaining, contracting, and coordinating with + your freight forwarders or customs brokers? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:5:question:1 + text: How is domestic shipping handled? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:6:question:1 + text: Who in shipping is empowered to authorize a shipment? Who is their + backup, and are they sufficiently trained? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:7:question:1 + text: Do written procedures exist for handling incoming shipments from international + customers? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:8:question:1 + text: "Does your organization have procedures in place to provide freight\ + \ forwarders with direction on how to export and temporarily import your\ + \ goods, including obtaining assurances that shipments of ITAR-controlled\ + \ defense articles will not transit ITAR \xA7 126.1 countries?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:9 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:9:question:1 + text: What procedures exist for placing a destination control statement + on the necessary paperwork and shipping documents, and who is responsible + for this placement? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:10 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:10:question:1 + text: What is the procedure for maintaining shipping records? Where are + they located and for how long are they kept? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:11 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:9:11:question:1 + text: Who is responsible for maintaining empowered attorneys for the freight + forwarders and brokers? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Information Technology + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:1:question:1 + text: Are all IT personnel sufficiently trained regarding export controls? + Is tailored training provided? If so, how, by whom, and how often? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:2:question:1 + text: To what extent and how does IT coordinate with trade compliance regarding + storage and access to export-controlled data? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:3:question:1 + text: What are the procedures and criteria for granting access to the system + for employees and contractors? Are they different? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:4:question:1 + text: What limitations and/or restrictions are placed on others who are + not full- time employees of your organization? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:5:question:1 + text: What types of controls are used to prevent unauthorized external access? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:6:question:1 + text: Is there a mechanism in place for tracking what and by whom documents + were accessed, copied, shared, or emailed outside the business? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:7:question:1 + text: What is the policy for remote access of the server by employees and + or contractors, including at both domestic and international locations? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:8:question:1 + text: "Explain in detail your organization\u2019s process for transmitting\ + \ any technical data overseas." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:9 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:9:question:1 + text: Does a process exist to label technical data before it is sent out + outside of your organization? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:10 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:10:question:1 + text: "When transmitting unclassified technical data using end-to-end encryption,\ + \ are all the requirements of ITAR \xA7 120.54 met?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:11 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:11:question:1 + text: Is there a system in place to mark or identify electronically technical + data, e.g., do documents containing such data have an export legend citing + the regulatory authority? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:12 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:12:question:1 + text: "How are cyber-attacks identified and what is the organization\u2019\ + s investigation and mitigation strategy?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:13 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:13:question:1 + text: Is the trade compliance office informed of cyber-attacks? What government + agencies does the organization notify of any cyber-attack? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:14 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:14:question:1 + text: Is there a mechanism to check-in and check-out to track the use of + technical data? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15:question:1 + text: Does your organization have procedures for issuing and using mobile + devices? Does it cover international travel? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15:1:question:1 + text: Do employees receive or can they access ITAR-controlled technical + data on mobile devices? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:15:2:question:1 + text: For international travel, does your organization issue and ensure + that employees travel with clean or sanitized mobile devices? Please explain. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:question:1 + text: What type of server system does your organization use, e.g., are the + servers in-house or leased? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:1:question:1 + text: Is there a protocol in place to retain and backup all emails and documents + on the server? If so, explain how long the documents and emails are retained. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:2:question:1 + text: If necessary, can emails from former employees be retrieved or reconstructed? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:3:question:1 + text: "Where is your server located? If located overseas, do you ensure\ + \ that ITAR-controlled technical data is not stored or backed up to the\ + \ foreign server, unless it meets the criteria set out in ITAR \xA7 120.54(a)(5)\ + \ regarding storage of unclassified technical data secured using end-to-end\ + \ encryption?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:4:question:1 + text: What procedures exist for limiting foreign access to the server by + foreign customers or partners? Does your organization ever allow such + access? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:16:5:question:1 + text: Are your cloud software systems FedRAMP certified? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:17 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:10:17:question:1 + text: "What is your organization\u2019s process regarding access to IT servers\ + \ when an employee is terminated from your organization? What measures\ + \ are taken to ensure the former employee can no longer access your organization\u2019\ + s server and information?" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c + name: Physical Security + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:1:question:1 + text: Do you have a process for visitor access? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:2:question:1 + text: How do you process foreign national visitors? For example, screening, + export analysis, badging, IT access, etc. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:3:question:1 + text: How do you prevent visitor access to areas containing sensitive technology + or data? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:4:question:1 + text: Do you train physical security personnel to understand where export + control compliance issues arise? Who conducted the training? How often? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:5:question:1 + text: Are export control requirements incorporated in all access procedures? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + implementation_groups: + - 7C + question: + question_type: unique_choice + question_choices: *id001 + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:6:question:1 + text: Are there any specific technology control plans in place that govern + physical or visual access to controlled products or technical data? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11 + implementation_groups: + - 7C + question: + question_type: text + question_choices: null + questions: + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-7c:11:7:question:1 + text: Who manages technology control plans? How often are they reviewed + and updated? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8 + assessable: false + depth: 1 + ref_id: ELEMENT 8 + name: ITAR COMPLIANCE MANUAL + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8a + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8 + ref_id: ELEMENT 8A + name: Objectives of the ITAR Compliance Manual + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8a:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8a + description: "Organizations should develop an ITAR Compliance Manual (ICM) and\ + \ make it available to all employees. The primary objective of the ICM is\ + \ to provide all employees with a written, authoritative source that sets\ + \ forth the organization\u2019s policies and procedures for ITAR compliance\ + \ and that defines clear and consistent responsibilities and expectations\ + \ for employees with respect to ITAR compliance. ICMs are also useful for\ + \ helping organizations preserve institutional memory and share best practices\ + \ regarding ITAR compliance." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8 + ref_id: ELEMENT 8B + name: Drafting an Effective ITAR Compliance Manual + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b + description: "The export compliance team should take the lead in drafting the\ + \ ICM. After the export compliance team has developed a draft manual, organizations\ + \ should consider selecting various employees who work in different business\ + \ units outside of export compliance to review and provide feedback on the\ + \ draft. This ensures that the manual incorporates suggestions and clarifications\ + \ from the organization\u2019s various business units. This also helps to\ + \ get their support and buy-in for the ICM. Organizations should obtain final\ + \ approval for the ICM from senior leadership before finalizing the document." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b + description: 'An effective ICM should be well organized, easy to understand, + and should:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: Explain why export compliance is important to the organization, + including the promulgation of an Export Compliance Management Commitment Statement. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: Provide summaries of applicable export laws and regulations. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: What is the role and function of the ITAR Compliance Program? + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: "Identify the roles and responsibilities of relevant export compliance\ + \ personnel and other functional personnel who are responsible for ensuring\ + \ the organization\u2019s compliance with the ITAR." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:5 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: Explain how employees should coordinate both within the compliance + function and outwardly with other parts of the organization to ensure ITAR + compliance. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:6 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: Capture the day-to-day operations and ITAR compliance risks relevant + to the organization, including through diagrams or other visual aids. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: "Describe in detail the organization\u2019s compliance policies\ + \ and procedures.The ICM should either include or reference the organization\u2019\ + s policies and procedures, which should cover:" + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7:1 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7 + description: Preventing, detecting, and reporting AECA and ITAR violations; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7:2 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7 + description: Identifying, classifying, and marking defense articles, defense + services, and technical data, to include the evaluation of authorized limits + of software version; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7:3 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7 + description: Incorporating AECA and ITAR compliance into management business + plans at the senior executive level and various business functions to ensure + effective compliance; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7:4 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7 + description: Obtaining, managing, and complying with the scope of ITAR authorizations; + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7:5 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7 + description: Maintaining appropriate records; and + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7:6 + assessable: true + depth: 5 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:7 + description: Meeting and maintaining adequate AECA and ITAR compliance staffing + levels at all divisions and facilities. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:8 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: Include templates, checklists, and/or forms that are applicable + to ITAR compliance within the organization. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2:9 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8b:2 + description: "The organization\u2019s ITAR compliance training plan for its\ + \ employees." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8c + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8 + ref_id: ELEMENT 8C + name: Publication and Access + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8c:1 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8c + description: Organizations should make their ICMs readily available to all employees, + such as by posting the ICMs on internal websites and emailing the ICMs periodically. + ICMs should clearly identify an appropriate point of contact for any questions + and export control concerns. Organizations should also incorporate their ICMs + into their export compliance training programs and encourage employees to + use the ICMs as a reference. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d + assessable: false + depth: 2 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8 + ref_id: ELEMENT 8D + name: Updating the ITAR Compliance Manual + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1 + assessable: false + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d + description: 'Organizations should periodically review their ICMs for updates, + revisions, and improvements based on these factors:' + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1:1 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1 + description: Any changes to the ITAR or DDTC guidance. + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1:2 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1 + description: "Best practices and lessons learned from ITAR violations or \u201C\ + close calls\u201D within the organization or other organizations." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1:3 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1 + description: "Vulnerabilities identified in the organization\u2019s ITAR Compliance\ + \ Program, or negative ad-hoc testing results or audit findings." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1:4 + assessable: true + depth: 4 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:1 + description: "Key risk aeras and changes to an organization\u2019s ITAR risk\ + \ factors, including where such risk factors have changed because of a merger,\ + \ acquisition, and/or divestiture, or where there are changes to the organization\u2019\ + s product line, services, or customers." + - urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d:2 + assessable: true + depth: 3 + parent_urn: urn:intuitem:risk:req_node:itar-compliance-program-guidelines:element-8d + description: Compliance personnel should have the ability to make suggestions + or changes to internal ITAR-compliance processes and procedures. ICMs should + be updated on a regular basis, at least annually. diff --git a/tools/ITAR/ITAR Compliance Program Guidelines.xlsx b/tools/ITAR/ITAR Compliance Program Guidelines.xlsx new file mode 100644 index 0000000000000000000000000000000000000000..b38fbc4a992ad8795b64e5ef70b311d7c5f5e4e8 GIT binary patch literal 70861 zcmeFX^Lu5%^DY|OHg{}0nb@``w(W^+dy-6S+nCsPCY;#D-Sau$^PF>^@4bJ)IqQeD z_p`dYR zFGn*MeMV0^TarQuFzTNmV8H(W_xeA01twGUZ3dVz!mgm-kSSV=Vmnwy>b&dYC*(8U zK($@0gRRh<3l{=<7oPiZ)KNpd7G{rfp8UL}wm%(}&rFesQaO0e%n8$e&{V0JCpFI8 z*u3_kAq+?rR0rlTfUY?@`YjPN5q=lhf^yLa-6i7rT^OYE-JB3-ou;~0{HLbSo&ts{ z3+VQl>!p{GJP7*ytYw|>7p@G;0;!kw>@j8}bS%A>4ko7o5Bju~dc?P1zV-*i>8=+E z$`)1qGCWO=jhA2`w2* z?12cm(4_TXFwN6{vX(?L5ub>@v|{)fx7dQ&zpz8&4^H%9eqV$-ZhoLk{`7(27gQ9& zQ$Few?yFn;aomHXe4pS#!9Nq9VXult!{8%t@u&__M3@ZuOTkj!OGF=v7l(;vTb0%`tMFcFZZGd z2>}9v1P20w3|tvcTP6<&XB%S&2b+IktV&(qp@N9S zJ0% zkz&@Q6TjqeCx%}pL++Tm7o=`l)srCc!TR#iIu~|RN@1c12ckBmH5FRsr|&SIlhW31 z%u)W`eAqJ*()C5h!CJv_`5+{sVOBmwuY0IT#REpL7b3V?gPj6Zb|Xp67=bvJ5^;Fh}+7--wPwgLTx`WCs1pbWgh!C-B`4FlW zlBw*6RYr79kh8CG_n9A1^N9Pg@GZxJZ3tt_JYFTNVbB_zA0%{7KMsld5$-1}p`zF#-6MM6PRLUAVh;ge^@!w84pf zohAq8T(u=7V%o#AK$AXQn=FZygm$Eo#Qa1F(bP(ysf0LjbXcjiwr2%9x0?R8Hy-o8 zprSxh|IP3_T@&}iO+))2nWm0GjQWQz_{dq)5N6DA%6`x(s#P9DrQ7Hlhq66*Mg9p! zKGm=yHD>9&@@wG!>}>g78$l5*`RK9 zvk0xa3O|a*o;pkN-xv|o#4iJrb%XIRX59aS6fDr*CeaT4+6IoJ?P>}X?&!>H%F`WlrE0ICzPyqvGFxiu+Z z)tA+3x$p2D2N}Ke^SP`Ao)g|1UOMV+Ovw8ynWTt(TkZnL=Ii$gy5NK=vv3vfPE;u! zg9>*a3OdV>02zu7ye=)5<#AeH?q!}e+wPs1N^@{LL2dhd`c}T~2MrM&uv$5Do>kxZ z4c(qqEOoDDsWQ1~82GLs#Kf`uKYu=lV0ork$*y?aZeKRfX99fTgm4AfYtCZtlTE%| zI?#aF!yStB@O~j7nj%q{HDGeZo@^(SV+`1=QeV%`E-TscWC`G8t@pLa*;z}PpL;rC zgvTwmbjf^t?Th?{3)|V5OEQaV&v3~R?4J@OuSCfq_akA$d(KNj%oUEH|7l4jQMfjO zVr6u)o`p`4wvRi&Ki888EZo`$~TQ<$A)n z+i+o8@x+?>4*&m!7=gNNWAH#MF#@6n9taF55HbEoWc}Z9<9|k3P#^~e_WeKm>PqRi z{!f$%?hc;wb4qgG!g2Ga2{vfG1eGfsDu^VcchlYWr>t`iOwt!&gpz*#5(2DkYLlCFY{dL z``gdmBEr8MzDFXEK`UR-nL?&xj1@FQfw7EkFe|zYB+L;-dps7bxI*F;mwulQM|K$_+=;_ZMK-U?>F60yr?}e0N)=53m zUU!ywhif|r%|u(XUc*gkmJR2%?)}-wNzK~=4@5R$HZzEG`OymnXZwfgh^Bz+bFqdF zYjmwQeue>fWf;jCloL)#plM+dIqAw1vzk6UQhd}Eg{ymrrDf*uyF9tKOM$dMvI1-O z#uJfdgQOUZj?oNw3fkD+v0W)Uoo>||hCB`xRjg)=hjSwCvO~(RT^(F?UE;C+j61s* z?F7geL+RFsozO_iz_4IPL|^gYD_NQ>1MM3+dM_&a?t#s#`4+ux-~| z3WFR4Rwf@AHisT_o zX2Dv2kfBmc=NGH+wcg;Si-=_z1&gxU4}&hxwm^Ph@Wg)+scjNa1XYe~yofundA>$d zQn1x&TrerGL5bg-t0^`5+4NTITcB)={IQN|=DRysdO<~yTrp<#KR0c&PK;C}3+3~( z5CA%BIB*@tx9a!!ZH ziYSGmt1J$>=hr^XtEG~ND|J*4#ljY`!otMSg>F+kO^TyXdX}u~iY3adR7wcSwAsri zxKEo+YxdnYL%W~aRtY}>DNLDEPC_e#D7Ak?nis>KtFW`zDz{0`vO;Qi>{-^wph(J=duIG73 zS&GgeP7_i^Dr(seW{OE>V{>=Mse1eSos!l(DXElsxisSxD|4fq-)MO-fYXjZN+DfX z@{2M0nR~6#JGe2;22egk<$<1Adn=`=>A<>~6x zS!dZaRj9}1W`5Mm-op14mdLSR2b&qefU%{Yps7Hw4>1*;qSCKgKr0 zw)j<&w)!uE{CD(-a-Tx}PzC{E(ggeeLl4&fi5~0!g&t%(#{^)JFqM#4Zj}`k-d&t= zqV#{bo2S64UoUgHVWUGr3R7VO0bg8So+EeR=(SbYw3z5_VZOgbv8p3SwYw)~q*JYxOW=sf_%WGlD1vB)KcYXyAg52Z}UZRevw7b`caFm5C$4#79AW^^iPqsdQsz;pzL48}TW!-iLnypR(*b~5~5 z&M##gA!iCdBRfz-<^B!&mt=T4&(KhZkYQ{sA3auqI)2fB^!ROdZ7S6bLwR35*uvOu z-z#U+g{He9Q)tql(sKH!C zQ0+b}`z0~yGgr{Y>x;i{^XH~Jh3`>#-G=+EMueZNFH|@Ygl1FWuL~OZ!D|t|Q&j>9 zM?!ymQFBoH&FI{-m+y8auV2wkEn0J_W&ZVg=_ojt+6wT#W%rs+@88yH7VF^c#j7PNa$m4ibi(yL7nGG#1%cA_G&Wfl{J@jl|UN!aJ zL%BUS8*#xW{m;E^>5_+X0e99&p@EuDnEKN05DlA$CMKU-l@%@eQ$-=d=G5+VV!T>) zhc^;!JddI5uynMg)R7Qu2c-l;C4tWgVZum7w73*vJjun3YvG1_0$6=a!nJ|gqZ3Nr zXR3?QU|zI*00E5AC|56BZ-$IwIgffI>G}~vsXywK-Hu>+R!+^WPpIu z5Om}?y-*W)sPj|s!C$vJ06<5bg_3w+H9)>#mho=32I`=dUMEYr_H$m&p1C?-MG`?l z-=Rq&YTMRmw`o|ZuAxg?g$vvvYMWYS&yN)D0CJNwv*Xe-mgPuc1G6rdK^gM%4BPQI z=WS!0rngC6{-GycX?^Y6Mt?DzqgWsqE!jKIWqE{}4i4}1`rHR)X-l=a>eZ*h?QYqw zDO%CM07eiOy)UdrlgKynUw`($&)%nrM(@I=)-h-9K4IxnhKLk#opx`}Hx7N%2(Zdd zuNXm2E8oz~(7N8LA0BY7fOLdD5E+Fb+!J?e0JfYdRN@Tu{(kLYz!~UB&_I$3Yx^O0 zr=ZI-yG$uIIA0NV9@{H}D6!o4KG4lWb?XkG>t!c|u7J903JyF!zPLBcaZ)eWf=G6H z!2n@q3Vy>7jN1kk9=rz71DoOCA|eHWEl|9VBxRZUIT!EvLdcS;2#4E-t`$#Axy zl&M+6tCn!(6^*85i7UcvoG^1DaCZgS|;zU->eTKH_e!kMf;xYtP(v5 zlOs3x)GTAmhU+7xEB^GVE7=-srVg8-GuE(M_(}+W_bPU}PM5$Y7OU|Kar8J^ z*P}=Qst(^+hMa#ETRDvbg^?!pUvaq)eHXwCUM|_Q*qV>P@mvBc%R+2wlBWqHwZn^z zVPOC?c1Xvgndp2J(_E7a;oL73>ps& z5oYsmzjvHVP)Zkdk2Ze?pzB);cSekkb zg75rQp2yGeYfC{JZ<$s?E1gT4c3m28-jn$3_0-2v-ngG>=hG9GZ|6} zQ!DUt*jp97*EFXjy4u+qFCQoIlFGU2B4Q7zaa#v*m{A`DM}526pjiu3=jKINvjgWF z#bhgco4}h4hLYsAKzWf2FJ4LB%Lj;qYm&R1-ehSjJ&39)4IFyT*l>B`xf37t?r9?r z2h@|&Wr=)M8us{gon7emN9&#Zl`drL@P-PSCC8Q+u{~1%=9-ZOM7;AFmv0MzN-T!+ zQ4NuFF10B>fHI082&5HtRuFke<@s-D{2^aHy+Ewk$3V|TtjJkcc<4M$y8i1UGunLTW1lX9B415Ee>pidI4Er}l>CyXhJyflmh{4f}c!kS7i5 zLlgPZ3A|SsVm}PDSU%`XL1D~`Mn+xXm8%$Sp)2sH$EbPJr50xrJ>ULOLLFZ8cckI{zuszu?56)3fdZL^+c zBscEfgC%hXW-8u*A9FfSr=0}5zT27;8KO)isY#a_|5#e5R08el?Y=H8hy_ zBFg#zW&WuZm-m9*Edt1V-A>5d(MKD)1J{t>Lyq%yGqQSFd-IqxfDSn=R`uefq@O87&v~%ohgArx)A(+Z|wDvmjVE zEKIgcBZzbmbd(+{Mumc>OjEvPLhoNBnH_|GLqmi&NpzSCYvBzM ze$79Sl&-J>ko^pq@g zfeRU8Kt=j58Wd=nXrzxV9X{4WF3#jB`;1MeUma6zE{P=IdWi&PJNa zyP<<>LF$N33_fiwEzjzf>qjv@3@yAGE+vvVx%OPfTUF5bSAJ+wHNeU={uAai_&<`X zPAdI0*a52ld1*w+GftT{;rM?h1QO5p(6tVlmmrsGR~^xavKtu>YSH}9pr>geAN1)4 zS5$9ZHNrHlJ6RX=(^B;QFcr=CbT{fzQ*`Skor@f#Vz0d2j`tS92vv^ieH33L=^!S_ z?JfcxPRzhC)%>+)*qF8o-)pK|1!b*QMP&F$@K7l5uW4IA-;Pnx|l?IhGvDHd@%s z{H>m@pKc=+Q*S&xEzmG$f13>w{RvDdA6VAyhef0w;>WWRUDbZ>@++~;z#cfJf@5m@n zJcA|OC{K~nTe^7WDzt>ZzPui$<RM;hPT1=XS|5EN#p?fTXHh)kEHpf>*3w_b!K+k%}f?O z%EDoR%SJKdqNVhgmS}d9=9r}L22$aeB)zZ+v0H>XwP91ZWQ^aUVSAMvCX7Yj$!tgE z0|GFuy~rBs0D}AP*Gu;O31L&M-{%KoJTG5ZjW2vZ7A=Rs+5cdeu_h9wPJsLI$XRF% z9^tdd`eyuP4dF_HMKJtUXxcR{2zX9=je?M!FzX>~gkf8*GZLlD{4w#f2Tj?<(}42S z=4YDS17?s2eO9huA%_j_61I_!y*CTq>ut>IyxN4YyL0DQkRK0*jD8$)qh3whxNHm5Bn9qPS&>n8HmB zCLRT+RA|!W8Ip6e!aoPjSqV^cV&ZvroqaY#7o8>jhQl+P5yBm?!G3QNp-f~8TQX)9 zSV2O*gGe6fKaTD}gqP$0eS4Akn0rF#^l3L$A_=4`wJ`2q20X}sD;Z)NNt6`J%-LqK z@?711BYKb7mT{eU0i9UZCFsM|Ynj<8acxc@xu3cKjk(2@I36I$1@B&2*3Fs6)pNhs zICSD{)&ppfvk;T8SbWQq{bM@4(oo&XJ8!lHcS5zdo&0(stDU6$X_10(VQYAEbpo`j#BWO z+RS%R?0!Un?B5@<_0#hmntSYHu@bWZ^{rXe>a^ash}ecX>vCerQgRy;l*hG0pK7uG zk;D<1PbLhR3{lvg->IW##aqJ#op9j^kY(9=PCf`*2R_cXq=QhY1Omf4>IYS{wYl5X zrV`i~J~iKDGty4t@c#&#XskN<^cjzUhET5bq&A3Ph>|~~h1}X^tv=ZynK4^FLE);g zdS4pR8}%c zMSmd0Sd_QHy;#Q_m7%_H9LI|0K53yQ5pvQYV3au6R=b4)3EumPFNXBuHg=-9ih=Gv zbUYr`4G`)dF8pI5x7IUp@bmh|#G~{cg^AgmnFVp3vju*-6EVsI)Be(tQL3KV}(c3At zFwBX2aCW$CyIuSV7tU12M~|E8$o%6gNWt=H@$TE7pLTa0R!~1W0ZLVILT$u}`Q{HP z^i9<<`F0NIRYJ`Ic*{b7bY)>Nf#p7D3eZVnpjj^F({Q9$XEsTj^M_&iQ_;9b*34dPm--^2JFn?PMPn!VYaB1Q( z(oz3-7DfsObecZfw0>SoA)1W;QEz5bTBAt(9-#Me_}!Z-MyI}UYPzZC=EIlVBRCDi z3}GJNxd&}aCb$e|VA@4r+glsWOf^9ivQCNa=YIl;ag4C+KBu=)k63MK*3JmpS~rS$ zH1q&h(@hC6(6D9jt$rHC0XwjZP;i*AT5jbIN$%J&mf50ae-CeD+7EP?4}3-+Lcn9w zjjDu{r9oCRr1a<3 zjBNVkV>HYch0HPmab%Efi{}F1?r|RL!AT`>U$mpLGRd zT&LMi*^Px7ns5efC4+1I2#U({dnZVN8joYl^ zn5{`=p<*D6g6?Y{po3<)`F`rZD{yDo8Sub*$5pE^1ftj4Iq7JhJ`}0$H@w1<$++R? zwt4w|c3pFpg>7-20`z;f=2y>&TmP7Q5Im3eBm>@eubxDFJrZ$T`Dovi6r|(T(qmTf z7F}V_ieN_zk2XBl%z_2RNN7GDqyV1k7$+~i(qLS zOS-PQtKox|WxG#}5AAn5_O&t_;jGy&8UKV0YGbPddaKT{zQ=UBIfU)X!*ULU6P<92 z6X8B0-==}5H{0u92a(q4&PxKesc)+_XVaS8sZ<+nam1_V`6Lm1;D!2Vqw27~-wGyU zLNC5E%!C&=>e*4N((Et~9$ALNn4QAA4vtDTBx;qU%QMnKR<%SB=69u{)^{fo^f$r> zj)$Ga_|Py`Q%(M6DLHjj|%G3N?m;RCKberX;p29Gm8(Fl&T0G5kC3P2rSE zXRbM%`}&==an|7=MjmbYPMQ59jIhCOkn}a$72JiO^ssH11R?^o0cu$8ASMmPX|&3Z zS^O}jSn-oQ0G&gxH_U0rRrVmGDH)++d53k3qpEq9Z4sp=KE1uRNf4WKvFP0Gf(VV0 zGdFSJcn^4&BX4C1`C|0?roMt*+{X)%z1BSz4HU{r);O(k?hX5DK4VzYj$@w+JHs49 zW#tF#fJh_0b`NxZ52RL8R{NE^#{1>ml9seo3$gXj4jW9^J$H5smi3>blW-_#c-M1b~>{% zy#Jgs<3{n+!}a#;bJHEmEymOD=CEi+V((Qkt_*$@uMO2^ELu)Yf{&#|sCiO&sLB-a z^>;7tf%&*g^;VA*Tzl7Gh3zO36nj^2Dai3?gtcm=B)W-*gU=~;>)o?X%7&`AA={ft z3^n5GJ7H_zn-O-d7Ya|7|KKT%$U)@O|K0-mu{@E zyI|8RkR~8ZyNh!Ds;L8e(ikE#r`WyqLbl-=0r^kg*z$yZ8F^w|iVv?3W{lC%T6^X) z{s*men*@nUWJP;_zh>H)r5)g$eK(WPU55>|?F=_0H7b-Js;HG%n{kk%kPS-D#Z`jx z%UwUXZcaw4U$JfT2XGdh#cU9G8O@Tq7HS}l3q)f?czXQZ(+R;VLz}rzi?m8Zn^u_q%5NV@Iuk?Nc{WmD3KRpsiuW_<)A#U{@jgW~6Mkgc zw9J?7ZdVGUrClMl64$Z~?QjUYms)TLznj&pseq659Q%wy!5Tu<$w?G%DdFX73ZIze zWlBaTwd+))uwPYfOLUw|9NA1=$$RX!SEgE;A(AES!{639`(__S$UrEp)P{W7EaHZ# zU$T*`$ZcH^uvjK#_eS?%+*O;S_sjT!Z}QDReZ%3(MxX@NHhf|@*o`IoOo!|h6*R#d zRF@7==HTcSa9yv)XS+YiB$++6zc2#PY=^18!}xj_k}~rKpXlQjuB?~`HBaa@LdqRp zayEy7LG_^W7`k6O4$~@i4F>x6F9N5mmVQ^@Y$o%);|=bt6ZhbfHlcHkqgMd#fYFJ8 z+|lP1at`RVmR3-Kow!Yxw6h(9%~;h{utnFlFHc&>qGr`*@Td{t6LU<1iS0_?oqy}Q zxaYCnx9HlmHHtB}zm@!rJ42B3z+~Rqd)8=TwVA?VP7U#iC4-3T92`DA-iSjYht;oC zw}6<)paNgEG=HT;0u@dnknSuO>(*Mm#}1;`G#rGfxb%!}LVl^@)Nci}I*|>`Z*gfs z^9QV{Acyu*w`NF5%WmgDd2 z!r$;BOP-@Op<_DD73@};3;DB*Lc~-#tC}NKIc>mxD=--leqLx>3juVknqzI+?7$7( z(u~6ef9XITa<)oh+ox1j-LR-y_;e5(wH*6Uvor)=<`=BhM1sE!K1Q>tx3rFQCT)Be zb1?PhUSU*pr9!^$FMDJ~pJS(6Afd7>4@Kl|GsS6`%SVGCOoqTT3G9fju+s;dN3>Lu ztRo>;Ak96}H}4401w5YSK}f^rf2A2icT({To-100t6ea$ZerDM-oJ2O?nreAOd_}G#m6s**xV|0v0nhjbSd~P+G zeeLwf&sNWA52)BqIQGjn8wG9(bbFs%#Ig2cpE6W1#m4Cbmld&sT%wPnRBf9_ca$Wz znWx#BKs=|>4(FS!w&uGUp1l;g!HZ=bp0Ig#DgI2f$ApIyA<;E`NHdQvVP0o370>$G z0s>OsE&Zz$-y8=%-g;QLf0T@%o~D~l#k)3Nrx=nPVDy4V4&cf81D!)Iy>f2zC!0EB zg*KwqD#6r2(jhohhrFZrQ$MfFA4YYl6JN882wE*Vb8%i z@8$DxBjBCGZjkq>F?aZBhRY(ThCiU(fy1Y=IO3rqjB!EFv|A^Sr^P`2=f>KsU74V{gq1r8ihX>~7mR_roMvs@R;jMc?I~x6E;n=sUW4Z_E!MhE6ru3W>ds25z z==$vW&ST?V8JAma35r95eWbwSOFoD)3zSYe(eqbP>!yY9^-S#)6 z`dQqe%W;%W|BMyk^St6mp%K)hNw*ZCki5=)uYTN-%L?31QSJ*U3n4}WU_#mvvHbJw55XDeoZ7)n3Dv1z3!&H*LcE6=|8^kM z)o3Zg!IU?VzQdGu@b9ULsORp_gEyq{!~<4qfoc7_=1VajzzjC9IrEHqh8C>N>0|b( zs0xt2_gcM0AO6&7&gjs(yrG5WLKrL_a^HEDcdMMohvjO{zY7%Z`wQUJuXXmwbx3y` zQk%c76OJCw_HB=Y)Vp-$5=rTqzFDXp)97RJxqvX*0G|o6X%%cx1&^jcHqbNGtzH8QdWkCj%1x zxk&;*2to*?JtU=}EboBQHnP^rWI~#zu+DVPi)@FbS%@q+5;rW1s4>!m z*S__wsab~xIR5!%5D=xG!V^+G{FqLEo2|YZb%ORm@Y{z~E|Pu7cm4xT&I=NNKFfrB zbE2vwG(Erh^JL{NTYRgOWVjigivxMVKo@mNk;=`S#b3 zJ5(eC?P;7Fs$3#2a67m*+Uph-2L%_h`WU4Sx9cOz#$G z28I(6TjyS<42c%m;P_XFolv6OfN;n-<2GaQ9lk4_jp9WHNUTJKS(&4zaKK+ruHbgv zRoqM~Hz3L-#8uHq9ZpM%@U(x}7XZ(!$@cq+|d_MAN+qyMQ3wM3f3zuvD@%B%MYvk7N`NGy7O1K z$9OlW`!4I*J1xU#jS`#3QvKBV&9<;0vz2r%=oMRSatb*xvPz|kZ`C{&iLB=BrK>1A zU97%$=#NC^*HboRL}%2lIfAwY3?P#S=*nXbVa)KinKRhR77u%QDrplZwx`T02oc-J zXnLV6W8*8Gp_J-TDA5pU|G5@gdE2S3+wUSe{=R{t=ix2Yrx)X2}x9J~u#>JHHfx~y4N)yyAr1$9c z0Fu*yv?58nuSJ%t2}cs7RtmA3^T=c%7G}Muuf8bNt2=!xc9fWG)2A!jc*GewBof+o zP;zG6|6$IQRaksb-N&nY{zpN{j3vww_|O`~wVa3(b&|xR0klvFcjvsFz$?ma~b~Z6g~t4Py@uT6P#;d)juX;7E>2 za%H`6i^tC`nDV)xlXB*(6VEWD3VqV^*Dn#_Q)D!WGG)+bw3<&g@`r7c;t*8$sV4B$ z-gXM0E^4Q42L{KAt*;ftETSbDs4FPD=snyrjWTG|)1(~!I_aGZ`5KCNJY+`gzAS9pHT zJj2eePn|I-7U_>L^Y)myQqysd7KJ;I>$I0~=Ut`fvRPi`y1Hen<0Ms{VY0VGN9gD- zX?oTnTa;)$dQ-$xLImJmh%kj}kAqiY{cvt<8&Dxoklpq`(-v#e5>*qCKWvK%oqcxNDi?(13uIZE1;5eU-Q24(WbjZXMW=Y zNBZH_2s%lj-KGIhY4n6pIW*%wz~d?2H#ljM?qh|y9+&P30THHR0^y@QjDro-{c$)2 zN?&?!V;Y#t1woGu&l5kOfzi+WWPu8$^_VV?Wau>ka#*D?$C1K~*}loi?P^DfHuyaL z*+8SCedal)2}E0dD?9*g8YH*E27;ki=dh*%5c`bj;Pivp`j351%%JJrEkGtV82X$W zSoP8Ql(}R2GI#F;QfwTNNhi$iISQ4a@P7H_m?!@*b44s-S`$Gachohc@o)?={cY6+ z?vM?xrSNxzmk4xXSfm4rG|HNr)q!Q8!O&)I+&Uqt4hY&Ihp~0Z*lm%~ho@Xp@>)b4 z#Fqc?*O&@UfAB;WigZFJxIg~@m{b;U3OXP$@D$@CqFIgolcxNPt8?ofot9HIse=w} zQn!5l9if1N$#HD;r6rj7)&W+PKiWYGDC=eL*WCh`E8-GNKLryV{T_~5`%}T0JA8T$ zkTi?!LYCMLQRH709CL8r4gMVWTN&-o2t=Ld!6A1VJHe|+lu_ylD>Z}U5OKyGgyF;4 zpSD4@w_VOsA_q322FV)iisZx!r@l42%f@my9WbcI`i%FA#4~xxagW05MW~Jws*=Z~ z@z0XvcK?*)I6BX7trm&LUttz&=nLge--`g!deZ>tnF0!jq%;I_z*rgB)WgB;!!+#*m5lM~}ry*S|_xe2vU985!_df0ZD10h4U zM*<5>$zYeaBKF`^(GB4zKXU{39vZCDNFwAQ1w^bb2(fiGD76EuG=KNRIY`QkijP`d zYZCn{9+3tQJ2MTt)SFZ^9#zCQ+%gW}sg*v~Wjr{HAO%78Md~&Ugz(pOhCnpZVRJ*i zebR1iezrLA>OHDOXy4}^bs(I_@0NrJdn^AcK_ZLUys@a2{gV(Fp z8Yi@MYQ>27fwEsZtZNSYBrzO?XRkL{ol&YWLR`Elyi$mh5%@c^MLozTUW^Wgd7DWWw-h__QDX2o&{OvfrP4NYrW1X zp<7qt_z~($X1N;=5O@J>;SE06f=J>*&@&XJe=oqx}9|Bmh3(ndrPe_ zU|ksQ&JuU~)#*uyCkqgLea{kI**Y(C5&2BQ>p>cZl2MmTR5q}G+C5dTtO5AIyF4Ml3-*?azK5N;(DRj61l8sSl&#I=+sS-chik~Xo+ddgemB&kKv>ktdy-!>dXZvjIUXTyHx&Xq7{B&qn#8Z z3^6l%QcWKWdBFz)(H9Ocq)Dw>Qn}E^mQZ7zR)DJ~Kc4Kw_ANXBzSQgZp;9oX2N&`z zo9lM$oY#lAQ&Yo;MfS9hpqjlF%H?H!-_b5Yu1AsUHuD0n-NKwW+BEzh&^_R0R9SMH zBNfMlSxgH+Ws^1dG9Q|gC=bf1thCn*_9y!$HB&rkbN&=z&idnHDwqpONsM{O? z*6?}n30;Xd5X?MEQ}i8hq%|a}bBo<)a8eE^D*`?io1oe_(~eFfQ*uSz{Z`Jef~Hjv zSH5SLYmJK66G>Rs^w@;d`}lY@V~#B&d{w_;nr{!s%JiXnc%AGonNV% zG(0Oky+43kGU2#;-Jh4xDpUhy0}_$IyFDFl1zE1a1!R4MMJmDQZ!$i=_N`fthzR90 z%(2;vxQ<1au0;yD997O(2`auhvp+q4VELGDyVvo`JLA_W85)LoPg8k9YDm&GD$N1# zv!!!v8yZw) zo^DTpd$B>R$C~=kUiCqenirvqSLs>=(S!qls>~il6y2rQM$~R*b0bf%J1KkGw`}5O zV23Y(kvE-bAvOp5;eHq4*7u#w#I07xQqi! z!RhIhpyeVDx2YQye63|zWD%NC-(t0e&t#+H?R0FsiUWPwSx{}{31-86IF)W& zYQf|kEtPubkF_m-NF~r@E+}*G_u))ukfyU84Uq>n3BLOj=b#fl69Z(_Pl-f|opa-5 zuy;_HKE9TzQ};>YfLyQ9bD3+v^SLz0jq^DqYR?n)%MQqdDFF`{-VU07=SD5hnU$5N z)CKyUbK>ID*}%Mj-fKGe3FALxnDC!YnDBMQwvX=d2&rAK*!t5X*NkKG4*1=5&q2Nf zAD>2AbykCWi*)i>w|&$_+ez&iXrVe# zSN#HhALQo@#Na}NZNpQ4{H?$HbeHrB)E!O?vrTvscUnS>c`l0bj-3FX%^rF*7C#*2 z;v6*!8WvA>fTiKUsJI5&uMtC7%Wy*kO64-*7@&$t)`*>F!mGkTShGYbnt%EIYGmWf zo+T%ni4*Qv$w_DZDd`<($&QX7k~@`t^$DIPntiByfAQC$;z|!P-zWiBrtJ5+C*xGN z>-ZFP3O$5oM#VZ{C7QRgoXKl_T3+jLUPmA?*8(+?nl0DbHHnU_agEa#{68@j)7Rp* zucf7H!<R04HQAJl)zN>I6S>V2Z`UwXc+zRN_Lx zby_J3CQMQa&iio|JZ_fERQy+dHy85lTXQ91Ml-kJfi<4}*SNB^Q}<;NR-N(3Z%o-# zRtNL#$Xz34b_sef8Q2F^We|I&URHU=X=ySP*7{=)A+@21#KtaWw8&B_HlSqyU(skAUT+}{hEQ+Z89C=VKn9u$W_acYAN%W;6 z-%_G6lI3#$k8-&jP0g;I(^URE#xr2SC_}Z5(`YFq1rUPZh9c98Lg+bG)oftcH z;b(JV7zK}9v&p@5%}yh2E6|BB3BSgihBkq<+3TEo(aCZ;b9ps+hhvUMp~(Y9J|f^v zzGXLk*L{8$a7F#a#j_Poanz_P)Mt({<^Fw&;J?*Gdx%N@(5?Dmw7EsO4^y(?9>`m@ z&);XBAEC2Y_&f}S zsUKOsDLuVaW>@Gb z)zi1rz}j?e7s%riH0CA$me5O>X)~3!;6YChYH_{JAI$&M)gcdZQrO+Otaf^a03VAP z^yM>QT!4~vinPbLRAAjjT20V`Z}I>oBa|lB8Kat8AtyZhj^$V#xZXr}A}?1XjiMKwJ3R1rCRDt6I``JT>2fZG z#dSZRe4>njpFZn1+WyL(0*#7;opal6em$cU=qFg-{AHL-m&J4_sDg!PjS8Zj;{G&^ zz#%F3D?P)%`Im3g+)@rK7e6t;u5bO={n%4?wDkf)i=;q6t(es%`w`4*SzFqJC-Dru z{HK1$Cy?rO0yirT%<6}=^;|Ie_?#{n9!dfGoNi5R@%Np*Iv9GmfdRHjawH(N{xc|C z#Kf2k%{LJv7|AoZNX7js7ud3x8c4RyZrEBf9K>sW;YW+oo$$O$Pm7^$*HTAAd)e)%WPGmP9Tcv1tO6AmIZBLqqZmvy0#9kMuA%rK%5CrMuwL5F<~P`g&gXSCve&2kKGe^X{j z2z`)kWYcutUMvv*x6^^iQNe#O?244mh^l6WZE}|jRHT**4Iz%b&6Xb9BDorz25TfL zX2;<3{0V3obqU)%49KZAPAXdV{5w{jTpx8-9S`xpL7LRB_TP;PdfDU z$9Kh9?azG9p4vz?|0oMf>+biE#o0_^4anxdYHVnsqZ?ZrV1dXNk& zZaD4;>rJzf^QkeF#}A}Fe6f__f_2;cG{QQefinK@MH!o3R~m$ryy-0u*F++{d?A;B zFrSmRS+R^9C5Nz1e&U>eswTd;GAOXTGM9_6yB z`+P}ujI-H70E6GdWyZfX5$ zgYW}X0`pnbwEY;=nf8o5)k-N)k+#f(^m+@&NwVL7@B?%l(z*0; zaIccwcbYc4N$$2Aqn{{utTVYadtvHBJI(1V0 z?FEmDyaNKF zWhhEdwSL~%3%i#ZXFpad!ii*q?MFL^Ih|||1x4)5s%x?uJvGN3d*qeRbwl^>O+u9* zFX8T*7Ecsm8LIaXpygiYW^*{zMvn5r{1W8y8fJP~XNiG#JmRxx(K6su5Wtze0MSS= z0K*!^?Tw{xLsz+eZCtVO5Tj^;Ytyq-Hic<8?q5iX`(}sUYi-Kxb?ZY9)KM8*x6H>fOCbZZ%)uf8rgiytI&d-Tyq&M zn54lcQ#}C2G3yBJYyy-S2WNA+&|YuU8XAzB-u0VVaZGt}s0IO)-7e{|=h>Wk&Lv$N z%+HdYVALAW7P!+6Vh&L2xAH%~mEMGQ-yd#}BVJAa3R@TGV7KGBzfRl^hVoAO&m2k6 zQEVuRtDC*5UXpJN!7RAFnq`(Y7-4AWns1!Mx&5q@sLuD>e}`#?n5fidj3rdaXV9r) zJ1bY63pbDhKK(SqLDVn@A^qp#^L<*i-Baws++}VWi>Wn9pvkGg0~zcs-!TF4!9Rk# z!xk|XA<90YjZQSV>pnGB+=uA8hR`GIP>&hq3%!gUY|#iT2S-2Ld?asIarNL#?vJd0 zY{(oa-3noB;DV$i=OFIufS364fODKbqW^lo%_5s46}FRtj*(1&;`Meja2-9}b)Zy^ z1jWGdT?MGFzCLj4W|LWrJC3Y(3RlFebWog7Y7nn?k~OdcSmPyf&tl|!)9e!eGu0le zZS2;rD7UkY{AV;G{1DalJ?XIR9(y{2U4%;V?yTe6$VtoI=3U3OIWr%IKjJ|6(Ql{= zHlBcxeRA@>`caz{fh2ypS_q3_%;BNvQ~_kZKP15&FBtG^qy;uIjtB8p@I^+kmh+*R z_9OEigYmAahtb{@z@S&!yxN4027#F5C%#CV&^@PQUW0t_DAbL2=S*`sLd_-;ZvQG~ zBE@*UJN@{X!jz~uAP~zd2g4WwUr11dH-A!m99DntU%eHRmuWr{j{aerp|uXnap<{# zhPw5((Y!D6isY&xC(F4|eAtiT1~4mW?9C`1IE@dxU`hG~bImAt$N4$>uur9YDEY5h zR|aoHSAj_+hX8#co!w}H1SHQ@*neZHZpe5~dHv`sH?ywqQ2(KNgdVB^qSlW%^82nW zCjIH}M8q7V1^dKUtL5vPc$k~Rq+j%lA`;ha}pZ1dEl&F0|^^TIh_Ws^Uee%3d zyaiuVr1YlQ0Z~2UHKIMOm5=5itilH(ddWx4-KNn#Zdl&DgW3YV-KOw0TNqvpodwt4 zAP*4JLzL&7Z~b*ZQT`g8eYf#-<>K>iBZX=Ec16Hhz#IqPtw7f%UY8^2b;j}(GdT== zy`tsSyM+ZPL{W3`Juq_gJ<(B(@AZG;v5;tImC1sv(cmI8^slp~2jemb%g?QHy-C zNP=ee$iF&YoRXM9Ut)j|k~43a4A%J`-=H5F>aXJQpL4FJ=a@DSa35J#-e(<#0l@s7 zE75~xVle+{AdhtfoBlKbU&spF$5)%cC) z28|lF6%&^J1*{*e4*-=9kU%2h>m}GUE{;s!>L017rQp6z*y9IOsH2dG%wI{lu@5Lz?~w^^6+6Hwt;bQ83uUIaP#<{>dap9_16x2v zXu=yj$vO*<0M#zWr?1C?loo97_f5g(BQ0gSMLu`}Kt#DEWo9=I2gq*Gk!=C{#oUs$ zfq?SX9FS-gW%FPWF#LpJZ|M#D0^(er_Ohwzy11>j#+_PbMyau4Af66I3J(AMr9s}d z!hpzW_7zkr5Evbw;ELN@d95Zs#?JYA_Gy!wu?V6bB9o)C8r5`*0 z0H)Ay`RbCl^OhJd%MCU8c17Ff1r%l;JlHg{TeL(3{Z|IX?s&+qaSHIGi<${VZ@<&q zW2$X-r?dr^qdOr=N!SN>Km@SX1@q~!)V8t{`$Qn@>w3jWdsG!)@t3&qJB~bS(s6Xu z-KnVG>C0Bz_D<{yVXqSCOKvJ6V9Yhwk53_F1!^AK=|Tt67qt&mL@kh0YHax+e*kFvQfVHn0XiQ{h$zo%jfhY%q_Hk1hG{Z?4v(i>d0d#aY=HJHz)qKz0{ zW<-8<8n80@bNmVA{yxPqp--`f(aekH74g}A%+83ZovJf411Z{}K=?Sq_?SA-fQee~ zTPGSfn{z^6pAFmfu|DWz!{TRmE(=Yba_3lXBJI)c*UUQh;i~mOZv|GH@FSyM7t|_4 zZ1dVBXTUe%FN8u7j}N7Ks)WoqTFbWvM1JXJbD6z=@usov`|KiAXkN#Y_DxF22b}uNASI`iuM1E+Pw^ zB2gk(II`=;72^54=reEroR?jP(#)0nJq`~n%t@jnvV={V^ zB~?*QSm`sMVfU$SF$!s^0qtI{BJyYqxTDgl(e`5X&GWs)`j%9cOemY#dFRku9v| zEQtO7>Z3Zm^X<7F!F=#!xWO%r}sXp*o z5@9AS8L)6%m>7Fu`?q`9ozPrkB_FOKyYocu(lC_<(08ooxLHLudDO79F~Qx!K7Zog zz51}20tjNOML3Uixl`@^RjtTC`1K2iY_o*EDg;x-p1v1&0)lh8AmK>rmztQ*Kc3b+=J)Yv!U#cN4!oD! z#l&g<2)Dj?i_;*$O2boN#}`hu&_ar-9?Xhx8w1L71?F{|;9jtlI_mUEH>2g134mVH0v^WENmulc!A>4Ow zg>hdWFj^gK7nQ$g=#C}M`-WlI^UJ;Hg;o5Dry!l5ti&-4p(S85zh25W*X>cPd|O&o}8I2ej!X)J5P*G6P=Q_UJtnxY<}%$0L*g=1wL)xvQ66rtgE^D$ z`gSMA3_Zb)>XS5?Xm=*AA;5hlB;NTD=T=Lc*SvD(SHD3Xu*8HkNHFJB`&|o3^FBHG zwG&kJun{P(5a0j4LssblR#W2*`L=?mIaJJvGyacqTYTG+22!73ePsp(XZ5f!Td|Li zAeDUQl26nK3p-<{gme)kSk1DRH5x$s@SUNpKBdRoA|Mx+c-~Y(sY?+D!rxDlY{^gzqOK@)q(bB&#N=J4zbLf?ivV+6+n4{sCI+LGB6%8+dO^X&h|V)rczAY5VT1A>7g<6s3L5*6#i5 zw`#jL`&Gw{Ntlf;6w2_8#CY2rc(g^~>#>oz+ar){P?N+=Fi!dToLNBve5Skh%QX_k z?vLTZUkOYi=fFSrb9OFnOuMvVi3%H_z=6SE1bP=OR8b1n0$?~b|nrXsJ$fo=b`^uYJEy7!7mSJQY_lf;YiOd z$K!!@dIxpT9C*1!;oG=bNV%T1Q&_0(NtgbFW^FG)*s)KY0?;LPca_(dPu5w|S@2EC zQk_woIrL7n;xy_;6q#=KZPY%k0AE1n_wL*9hi}+dh3!7iToaA=W=KtEv}z@e&ZiiY zJEdH@5_&;o-c2oc%dGzuY38@URHnK3HRn*N!+3}xY<$TyI3%B z7>;-5H_TNExqg_Z`_JRMg*Ty`92Dl3kXN~E$N~H!1xI4~SZA8QZ12$tGX@`KOentS z+cyG~>NI?Oht{zcgJX)EPl8S)zqTcJ&!^Z;cMiaM;gtnl>xKHMO!V_*&49gQY8Ad1 z#lM$VO0}cnzr-;1D65{?-&UukZYn%qaCNg?S0}MFnkLqUZ#ZV z;CB=3p8QE`mwTzZpm|P1XGG-$bcm#QTgtM{Ygm=7`VFsQd|G7R#Vwo*#PdRWR$B&( z^+FZK+vGm6I#z>rj^}{pVRD740O}}j6rrKh5WilX(sVv96|#c&pjC-fv^=1Gl?Y&A z*2IS&+O#l;Ec>m@#5Ykc6%8X_tQOu9*=ionc)M5+SNO#QZ((}ALW{?@yy$1r3> zWJZ_$_HZzzA=6+OZ~ILp`l_ZRxtf3GgIOLihn>m4LqUT6)2oz=y1Eoh+_DdjbRWd^ zF=zYLbA;I3w~sVS7jv4%sV9S5yb%qKw*(K}K1=oAYQW%kF$2{!kW1#|;cN>JEeMRs ziS#;cPLRlMJPeSaZZuj4+=+VKyk{ddufyzxIh|lycQO~o&gmy)-nZ1%vxhv4!x9)Z zuZ3DIFhq{#VNE&hJ21-Bgxly%EuNRwx^{Hu>=O;89yy3YB=c?J(`^OUA>t8X)%tch_-9N~5B7(l$plzk9(}+EP2?^r*M_!5;d)r8kJ(JP)F7QkDlsB!5-+$)xbbG(uysePx z=741TLE4W0)!6&rFBz%6IfA+ZN(Vp$O5E|k5S(TIACi%>F(AR&5n$3QNN~1K7|xy6 zC@D6oy~Sc_WQ|p<*1*t$k6Gp8idZT^n@&KS9-MtO9Wc52l_rqY_zkvJKApP69#0V> zilxY^nfK$65q?@wq*$BH?k@#pQ*5N$8%)Q9Z&8v{!XLe7&ml5`s!IHwb@AM*JAt(qFz3+|@=x`Xr$8(8s0hV4 zs0k-+s3A&X=>20WeEu5AiZQ!5V|$JFygPNen~;v`f5G2NBHT2PXftL!KHg*PoPb{Q zWA=uV)f;Yo9OxKCv}jo@aFULG5Q*cbY|)DIJsxJq6!BZBzz=%gEs)?K72#Db%UKD7 zcT___fs*LZ(|Aw%K5p#B`o2X-m5WAN@-a4#|FV4 zgYgJfEUo){-ful32=BT=hP%4rj%!t}$kc;Z_z2^L&uJNoHj z5}8f8LpR@6sGneDU8q4xA3;yKr^6}qso+NQvc&YV)K@;NysUgorYd35V%^Y*kin>& z!5^Ff^Q!=WiF5{&kFcW+>UfLr%F~GZUkN~H!T(!p@_#=V!e zTXzB-hBM8C9l6GKj(^i}VsYZ~ERs{u z`HNO_687Ug-p&q$g$aA>$!37t5C{2xu+RmJBXj*Ly>!eQ7i~)&r}+FwY%_^ zK13J00h!VDRzxQDGGVK{w)dPXRPRLpN_e62yP$^ECcME2F+O4cFBn9|X`=L#q5W(T zRrBK?Z01TVY$7C=ny;}yC~JR{kMc)i9TwV|WC@KxNqDkvoFnMkBr!TI&86JDB+^?V zp>szt*7o#{666sYiM|ail<4Sc4AtO)uhotElU^mk{^SoCK!d~#rwY#&D@Bcw@r$KA zpgTumHX+hN1y?4OD|kT=Rc9-gej2bvme!*ju%3xAgWJtcgofRTH*yPW{r@K%hIa0a z20UuaCl5Vm0V;GTR5Piikuo_Ol>&X#aLUU}>$ zX&*>QCx+-u+X*Xm&|`rk94E^9fl1HF`fqEH!4c$w6Wq^>ePKazt>4F-P?#3tSC_7y zqjE61Jh6#=Z13A{dwKzpd0mCt!|~h6M3u6gx^|+0cknY*h_^VWLv;z%(VCkorOx$KW9TpxEw;dPEPT!=QTTjSOS2$~gE&b@9$W3)hwm zNj(c~qK!(Oem4Q%rbJ?(_We2U{N-q-V!K0g2(}GP+0#hY!SF6+;t=BQZg!F`dEv6~ zlh$e_u*wHg&jOd*;{2;h5VE%cpWl4AsFK}`DQ^`Q z`>q_aLLy_|PlfcRk0yMw^kMgA%MgtU$0Tj3(<^?3WG*N*4JD_t;t8hFg>i6*D%9!r z`4MsK>wU9k%AEa$PdsN_$flCKNiLsk+(!EKeAwgrMR*UA?cE)z>2}#S#{W9on9=>X z1PT?ABx~r0r}TVWEjnJn7#ZhpcDtquWoqM{}5)~Ujk7diRkA0FuCV}6PA=8okl8A2hD$!`Os!Zu#=Zv zVYEB;UA>(Kw}S18br`q04VI^lh+m^9R;Nt%kn9`IlyV4Wa0(?k!YSaHmpr=UEl6pi zdc=vk^#CzgFt0SGY=IK|IW|6s%|ZP}R3bmk5jMUWbI2P+D^a4=wllJ+L;gzg?w8PYGQFJyTh8XFU zzsX7`)(1^Qm6x)**Te5pZRrU<4l1qNg!?CnqIvKIzWS|zSMfVrfq9le>Vt{9(!nt`+)p`-Ih)-vw{}zx@$*PtzW7Ezg z60)fVgYibVVG@wWDT2;|`D-qYekTa zAM+Pq*9`2r$7VR72(Xs&7p2CT_s#AruxkpfCSDoh(1_c9tC_2%D(cA>uzsOA(Skf> zE#|l}+p5ziC?%$R&oaA>r72*tPqWb6t(BioBuL6*rnqCsj zit);$y`b&NoBzW}y|l}}gb`zyPF-z{GP34ZAPt2Z;dDVmC-74l+*MiE6(L3AzLAcr zA}@E&!WT~WoYH}jyS6ZsPAz~*KPt5Lgr8%;d_}Xjn^kL=4k~65sFTXLdv9DU-n<8( zZYmTlCr?&1u}^Sj`x^X%?vEGMk?r$o%~Lx_85gMqn|w8sq*aQ$ITJ{YmCaZh zq0N-exLRemJgjs6*Lt^V@F>-p-l`c#yK!mhNL>5r%*5of_M%LVfGatmLYuz-rl)uI zhiPb=`c*K$W6`ZVVfC!cZ1t06&s+s+|8VYJ3t@pwm+BM!r9_SDDJMab-Xh$)zR)|? zNf|8)!CDEbArG>_`8y;Wd-ol>cqi|5JNv$UQbrA7`S9Bj#Xqt}!GO_jGhxh+xIoxw zD2-j(($Fru-}p#@CPgGD8A&b`%N0odM=Td2b2ibQIUXndeu1BMJS5!xGLB%a?EuR^ z9v|zu^HwphyF7SHp@M#Qw~o-ZtUr#An*C%4&bNL4YfJn;bHr`w8X5vX8Ax)l!N5RC zNdA+7#L>y!%GmKghVP`B=6{l3`TQsO)n1kZ{O^CF5^_p~aqUY|mojf>e$th!c=#n$ z4e4KkBQO~2=1TFZm-l(#hBySs-`acUdaFeTdzv{;P+Oe8u_unsN&8mHS>-^lTGVH!Ccz`14icpMzDpO8qczIg?r#;&VJ}HU)T% zm$53<2yN9ter9^K@ry~cR310RusfT$RP^(coH-=}a~zqhXxJ)fQb?xRuc-*IZ!83B zYSvCPYr1rltZ*+8kNPa8p@BEWo*0B41cj?9aWDxQX-B4eUeh~8%#*!e~%9O{Dz+ZuC zMM-Tql=64joNWCLUD2pH$m^M?%a(}QZrxorG=6w_km(0`z@QvpPUfA=W-Muluggdw z5Y71TG|4ZI<~>(ULycBjw$IRd{a8qhE+Co6!0WF4Tuk#$6{<$M7iUP>Wr%dYdF#-N zoGaH>9B}HjzdQOs#Ihj3Ru=9OqFfC#%VL|p;V+T3wdBjXRdIKH zu0diU#*oFf0iR@&b$&n?so-UlOP~Em6#hBsj;O0|f7L2~o^t)g2@ZfxtPVpFx z2GIHSN-p%T^!h8o$XxS71YD!lft+qCE<3V-$k+eW9E7MXmU>VmLUl6*yO3F=gA_f zn%?eJ>d>%;DRJ!7+``-37hZ?hun`MuHpzSkQ0L;p`HvIip%8;P7XApWv*g zewn`*z)M6cox?E zmCZitktstjeY{B|E>XBypGS$m=vXUg=T-k~O7_N+sgQJPi0@lnN!t@yoHIH*DAJ{{Fl( zSd?cm3q&UX4SUr(j@cg%#;t@9o0TQA+vaccws1_1oJ9AnewR3|%@YUfXb7-mYc)`3 zC)-W`F2^<39Og*WyP(ShJ*vyqb1yAgHcg)0#Dx34ZfHBTp!_YhUhZa7W3=2f+`7?c z3}!T;ru*COeahvHXt00%I`?iV|AXKjQ}nu;HMcX3Wojli^l@ca2+aBFqgy)wE6;j} z;%CVd7k~YHksy(_()|XOZu6Z-thc6l7phlxhG}5P`2x?M6A{TZNPyzr1aZLexMAoU z3gbxn*Tq(G*DjNs_NNHFNymP8e-xo@lyx8Aa^zdr(|qsWckm0r$Jv`I`kCfPH>0(X z^MYQu_c+tR>`MkOSC`8nVK2`uwTjj78lC}0%y7%SD!Ds z3x548Th)@D|4%0Dzv_P6O#}ne-2ex}`kzc_rte^Er0nEiZe#jiLOk%^upwFlg=Ip1 zpn~_|N%@Iu%R1Y)A>l|ToqpF2F2r5^L1#V=xwo_;okAS6?hCgL-J?JVP5`t z;v69G{IWNdP($)3!@4VTIl^V_{i;v9!TtIT`1z94y=B#m?bERdI%n0P?R|HDYQkn| zb2cT?VUhfNP_7MF)O>gL{%~s0;C^sow@kmB+B=OfozW5MDm$KlT`JsSZ0Yg5-W#g; zi(0AJEI2zp)ZCq}mQ1{w+@~y`i!gme4%{mx{;itE9+&2nVQg74h-!^#d3fNZsO^PDX5%C$Kj$NC6R5C7%X+hYS% z4W1lCrD<>xG!IYd6!3C=9vIsIg>)>aABYEV?VHc|tUaF3YQndk2D=15ytd7$X65@{Iqb8vgru>M93NB39ZOg>;}T+gh4`I1XZaH7`v%N7OYe{7 z4%ywhfwFV`Rhuome*J<)qt90I5~yWbG7;J@2GhaO$K3>LUrGRF;_`PX)@1!x)kq>h zW93dx`KNXNPd_Y$^al)j-!)N-dhPxCYC9x3pOw2QNx`~i0gJsin`1oQVDy4eyZvAu zzbO}iP&9*UFW66w{nfJ?$FhJ9i*?lu7rijoL`r;@(V=Sx(U29_-}D;4thNwjIeIdg zk2X43$C%_7?HvPktyhYj>kkEF#_30oLtR7|^)bI{ZD^*jLK}Z4NGgWv@1Fd$y747` zG~X)8%^^`vbiDgtc`+%>LX8Ux(WZC`f{;O1&m`VvvXE zM25R4PZM_6dVp?d3rLP<${ap4&mH4xlL^IpP@#-TH-S`FNcXbCMkyaK4t~-DTl7{- zv1?|^uzh9cS9s;sENL)-j3cR4rYTNos6hdqzu<(19F=`_Kbib$HO*9d%;oMVN>p-g z4cH6O=)=Tu{Q!KqFW=IdT3{ezKx2i3N%(1)EO6{nsrdtN%0_y@UJ-XsTG~Oi-<^TUNs|Gnh3THw-*veDfH^bhYk-R z*Q>(u;C^W@^oHp1PT&7C(Pp@WekV11rT>DN@#USo+oB@Ed!cwFdn4c$sw|@mY%p2d z?4P~T3_LSaWvNEhH_|!Xs*X*G^uJHTZxo%G&&-M-5 z)9So4A0DM=4Hr!79ivfe=`&xb3kj1gt9=x>SRa#^;=x(~3x_3LZV@LdtzWa9SH?3r zzjj4F?u0JgpTl^E#=a}tw($vNiN(}#_Dz_0ZgB9oA8E}d=!$leMX4dXrfMgpH8A~c z2zhDWyyl*DTE$l0Ibwb8mk>~aqqzXvNs}6e99HTNFvfxpg!iTgG@i%m0A0nGY=A9>V zY0OT8WYgLznY-L}kC&7as6np;aP8(pstwM_^qxzj8sGPpQg&B7td54Qdrcf8#gqtO zi$>XyWct9Z-Z&SRn<)1}gt1U}ZM)sxFV@)cgIvfg7BSx2%dQek1g=i5;;$y4+DT}l zH9n1a)dAA7mv1-lTCcLBTS(+TkK_iR?QJ!bkZlcHRQ-^;ET-98?4oKX-m!$??CuGP zN)^Pv-&3UOAs4vJsro9Qe6jp;$cG0J;dkPtRLATt8>zLfQ=NkSuUpSo)}qkCNqD zORuf)gpv5!n6$N?T0=y!Tgfuit$QI{jOLke+$#7OH=4DP_!kSpQ-YoOcs+bw-uK7G zLKj?xu%hWiQrTOB&QB$KIkYak&%h*owhTm$z$R#iD+tiPJs~~Qqs3QP{OHN1;9w9f z$l2+>;SMQZRL-{^N}2YfnM4O)!jyu55bmZB#MppM)VtFZ%ojq;2GCb3dQQO44p80N ziH)AblZF1YnQG)|w<*JPLGwCsfVc|g?h8PT+z#-PS}$?&heRgAKd(z;(CGi2u?H*7 zy8dqf<^bh($7zO0zBhxGyZGtH_aoMa)bp;w@sLQ2+;~F1l!j&bEk+hB0vb(mfAFlI z3>OP@1L-eGbTM`aH(-*h@6to}1&mb{vOCiqNu(lWV7`&orcWY}HeyWOiM0_XY?{px zkFO}@y)0d*h^@}vZTLYvuw2bw??OW#0`hNsX7BBimNDQ#`=_t0mHY)zLB45FX`#Ws zj{p2B*sW>!+QGs>ISSxew<-+m<~==fGj8s(grQnF!pS~4Y>8hg<c)bGwpF=Il zh^Rv*kcylEkPUGJ2`H=VnMvJ^kO`g6f}GwCQu&QeaXJVMFzy4>nhb$7*j z9qpFZ_uP*WO#A^$D8>sd8Dt)!1pF35qLtD2(2?(SJzd#iBj3Ovn~@>GLm_Aly7Zn^ z@@Ke(S-GpAgFIB8?H`-Tfv2r)l`CQ=r(+nxE0kuLG;6QY-Kku}we&c+rs^Bs23nH= zB~TNQxC(XtcGIT6!Wg~>bvwHl?JiacIT%ULM@SCA1p_*GURie73Hi~jXu*}ioY;zD z-q;btVbE(!p+IX0E1Sr^+C-fTccc{qcXtVQcX?J7r|)Ji)2W%fe+)cWlD61kp1eP_ zt12sQE%e|A->vi1PZ%%;2r*b-7n=B$&??r5k+APjBNef32mN5+SoX|=)G@o;Rx=EX z88?!8BlIkQ8H0rSiWBga$%MymJ~!k>h;-mY2bz;eC^8)R?idjCI{)tSvRr(0Pl^XB z9=FMfF@Aldd|V2>zdYaXb-pr>CVnPMKcNa`k#zI@DBJG#b@jOUwCc6w37V$kMS5L1 zgS;^6(Bg{dFZdS*b5c{`>`AetbEl|n$yEqDhCtva1L z+*u@xYx3LrizENfuTUFYVrrK2c#Q=ZD@nDp$z?yZGx zH~;bu>8^)fcNqT`3%!kEBO;sq_s(;608H>%9ibw+E?!VE^60G>YdkBaWQq4AePDjc zv)afK@fB$bT1qU|x(G&&G+@Z_?d|(nCNSoXcZ(bSQrSb^ee&^y%{9pq3R{Xcfx`hP zpTkgtZb4`t1sffE)qKVj!NTG0YI?Z?0e(a0%zir%WYZ+rm(rOaZm{-Ui7>Jht^R6= zI*KxmRbu>Z!3HKh|G0p(_YvtKN{YIha6XwX^w5Y7CDp;?@`RX&tY&T}L+VrH=B*;99FxR|AYT*F{&3`qI#6?x1&09~`b~jM5 zQ_YQ7kus;N$;UWL57G_TKhLsdXA4rn@col;AZOg&A4?hB7^ty`UTR+HpFeMzC7kCG zU~XmP83RZ|GtJ3q&R@sj>V&H?w8LLgn0m~2S_DFtHU?|UZ3tr@He2$PpsPg;&|R2o zuO>;k;`Mh+_wQrTQ3kvN|E1%>>YEx4p%vZ*6B`VoTs!MwYncW}SU!W)M7ByJ?G9kH zAf?GsHuqx-_emN5!3nPHj?LwLmK{4p9T60!V(ikNgv=Exg>^niO|VwLr`XXk%Evfx z=)P=)5<3*j@9k-UQ43c+7$2INyavjj)vVUK5&M|fDP62Hf28QX%Zfmob}oHsAc^Eq zA`FtS9HGIxNFplDV_K?OVH*jU#yI!zr@kW!^Q<%!FQXIV8Ir%$LwTn%I3;}>7(9c7 zSG2=QgAHw$_9cc8dro|o4br&Y%}h6)e3ozZR~wJVo@$Krz9GB)5wKE}hYhG-l8|85 zX9^;H7jA?*P3|D1zO}Z11oGaqGu?~l!EOZ;DH;0l!ak(Q_z52pq*3jM$bGCm^1JJ|X{^+*z2e(>uXD z4Kt!mxxn$_SyxK-c|6@jy8~SYab`1%of*YanmX-&xXR`DrQew#O7GZ!#GaRM+C%sR zuCy@me*iH+&cCsv=74!T>={E_L|AA^$hP_q zz8hIt?Xpv0Vy;!`$9+No5(&J__<9jamJJOgG9QD38JPJ3Qns+jA4=Eq;!^Jco+CQu zz(6E2W~mJyMClL)(hm2j$CzP&5&zF~w+`#nlsw^^~5_;XTi43o?dUb0RHN>i`EK8(cion|4pHbp@+#Kr|2aei@Tvk zB>(Fg6|lh?Aff^OlB)Ai6$7?I{Ska{g!_PMNRo8$ii37C6hIrJqT>(Py`_F-gb&RB zYL1NmH1QCu!W46y)vJvac4D1v6@#BNlq?RVZYlCBT~LUQPkCs%+_~|x#~!egm<({i zyh;(Wv4sIPe23C-Q{Va2IdSsm<`^b88f2DQEz32iM#vU$)xyd?cK;NnJR&>cGlSGU z%yDv<6Lm||?gSCBKYN>r}WO?~+RJl#LBbu^L?jo*Auf4Mc6W}rXiyr0Z zXUlteHv*4wAX#O3tlP+gXJ$g+Yy)0diok zbN!1opc^;npzJGJErZ;9>M4f~^DV1RolharX3Z+Y%YsF=DN3hDN(IV{xpUJ{Lk%=j z#76_Cu}FiM9LP!H`LZM@arVqDg$TjhM4*gVRLj=)bWjqAGJlXtuiWMC+cd0Q4B5d~%`OH-7E54o)?=vk)2@2)Pq2vvE@M^aJ zY>K?Rx<$lO#B6w|%}*sekeE)9`2pAg6gkf}2G+x72fjoqtW!+w^>#zzrG^*5Vet~^vA+lCW5mNTBEo7b!#F>tUgpz$Ys%AMu*8;Lk*YvRSLtw1{ zlvn6mE23=VNy5qHi9VW<^N#w`37RzE-`*=hzJ84SXoCP7K7kw-8-+I*K`o1Y8;O6( zj?}Fep5s|`1A57+&=H1dTJH!Gi|;WGO8{jqoid8){GcLA4MMnHx%BZUfXxOxAd<38 z&%pA5@k-6OV)c)*Q%=GwvSyf|Rgw9jTE^*F^v?sEnreX8%uTvkSZLWHK~)> zK?F{|GN{PIzNi)oidP9%8G&x5L_ac{F~Oit$!QiN43Od($t;!&(JsQC=@xNzM^ zJCZLsO=Zy(b1yOah#D5Pz!@rW8ZD(L&sK6EG17K)^6#+ z4IDH`wE_o8p$(bGV_?+%QWTu0>$U|)ux7<=1}(Y1DJ0zdNx1kxWnR4?7e4hD8^eJKgirU|3l`Pfeah8Ch{g z#5xLjGddc7SxRrpxY?6a6{#QSKB}3P)|Fmms2GSObAl(3 zzL2!jKBrpW7}&+GIzfy=z&7%rDC=%T8^uVDD273eARY=Ge zjw#983=uB@FrxbrlBlz zv!rJ(EJa2bE-v;Tt`8G&uvuJvjRmqV=W?Ktq8FhcqY3NYI+$jiAeh+jM_mzz|3~G)o0rhvvd#uumrCyJ{&MW%|{|Lm_VK0yo%s`4!1g_DvIsM#UDZ7&psWryAie^cWo0|ExOu?X(xE~UknNca;vqkM z5G%>Bs$SkVc=nNv#l?0G@ye?DuzeKl2rN2&5(x;Ykb+5o;2cOw7(rx}XtbrOVgpS;Jrp%|tpw`b`!xRDz7FWqYHzvltL0HloK7w}R`~*G)qMpS3`tf>WlTA)qV~ONmGrlv;`zG|S}G zavn*wOOcKMhQ)dB2Wp{AHsa*J0N;V)L-mW1MAY)eS}1yFF`G4|&n%PP57jQgfo|u{ z1>TXvLCUq1Uvvl8L`$9~*YV0c6D~|5@HiqpWyvm^*a0QD!Xw9*S)%pp*4ow?m~H}T3kySJPt)+t4k1%^ zXu^@fx~a3UOqC1^U<5;e5^1Bi*bJb;Klv(-uOXF2-fC*NNukl9F>E)pf+=jORQm;g z#N2y9)Rgy*h?$+(^CLvIMC)P+PDeh4Hr_4`Ma~i)D*4EU1*bGqLKJ|GW{3@~HaK@1 z81nnqzfu@3CJGit1_yYCo$= zklM+cOu|7hXPZY88yDbm?Fd^wXU)?jj-=gsnZ6t@X&NCf=5S9r~ zTwo^JmF-}UWTL6}`eAC{F8(csk4^y%K+oRObujZ+sLU1W7R{Qix*{|Q^(yHs(3FPu zK6HxIf{$VylofUic%QW3Q40wwo^+?mECstJ@YLocyA8>D}qi$K=3lHMJ5aZe*tgOkz1f9X0-tzN%;v_>X*=P)4rhj+PwH2$>U9 zwm{5R^_{}Jhiv&~Bm`nv$8HW|KEWC?ad$EZ|6J|Ys)xrXM@Q$69+e3c9^v2~#I*p* zAT0u;HevR}!+DD*unH+R0YU5t@k8|X_Y5wThrY-N;ifu1fAZql%NKwLOqMN^!Y_rH zpi>PN_sBBNn|u}zAz4R{7(^vMmghkOvUY-`p*EI(tv@0Epk6qhxX=Q-P%YXoGb7wjjpotah-ZPHjbVX1GHFTn#-_5*rr?tSM} zrI3K9XyH17=`y1_0;SH)UFod7-lP;F!anQBm{l}o!Juc0Boj!-%L3!n{W8DV-Ec!* zKSSvR2w&`u51d|}4P<^e<)|3}0CfYx$+%PG9jnV$pr9^xOfC1O*pzz)Gs~Sa#}0tUXZdH|(IULYHnk zV2G-QuX)Y%jQEwlD5oHBs`C9oaqU3<1>Sh zXp z>)saRg%=D!1362G>4K23PTs~!MW{mUvI*_aRo78UJVJGpckU294rmZnWJziDHm3ab)VP+Z>b(e z{`2|UpQBIWb!xtDDros$;L*}u&!PQTELC?qUb!&L164eSG{=4ey z!`IKB9n__x-vPEh3q2*@8|L=vN$l!lrj0k2*+C9?+5!7>5C&6enMEx|bUYUJ{IwCjs#cIIZDO4!4$t!H;3q z(H~`skcfT^=jxO7fc01BfwokWc@BU7+y8*%sP9PV%kuZX{ZFf)=QTbcx!c_sOZADN zN2MeYRsnWGQQE6#U%sw-k)HxihL8u<2Xe2JG4(*$+7nr;cEk$Z*cP2t(G!IUOIR%H zOPAyL)x-BEZy)iPB{$QsTtI^cCV4I$pWjL~Qr}p1*eL4UcuI)Xu4YsF>C4PmbPn=UhQ&tZ{^G zu>+Wj*20u0!)6BLHXM{aiDYLUK=x>0uh448LrV2L6V8uQrhXjwFLyfjzHqQqJXyw~ z;M9hmpuJ}l?~k4I_&^+CyA>$1IRv-__mFbP-ud`D50*PIetU$78lf#8ZDqW*MhUsl zYCrt89Eje{v`$uwM5+)67OQl#JZY93wZszA0_r;C@TS@`INLScw$jbK2U;qap~7&j zaO^(WhAJY7KO?*q9J}ZbYe#Sqfm0Ut-(^G-ji=U=-L zD8^IIfdOxq`i6Qt*h=OMtaN=K5)D_uQQDK+B(vJd_Gzt)6cla)0MpnY8tbsZ=iuG@ zZS0S@k^#fBPW*(@0r7sev>DIG30Fos<2@I#Uc(zfAUv>cNG!kz^)LJrkw-ByOlf*G z%&;_cF9H&Saoq9mB;a+SqcjkchCEK9zgheDJlo=`;UOzEbB@&)&)|^8n}*7dpX=iY z!<1j3L)%ZvSLtidUpzbb;-xvggK4b%t6v|ycz8L4Ueo6cFghclT zB8dA^gOCMGr?5y|uCN~WCZs5Jsa5!AWLvYm zWDg@MkdP%O)XfJKivWK(xleTvD){d_MiF4PNn27$L@kNPK(bDpHm<)Xnpjp6ZuAI% ze~4InUBqPQ4D1TmhNQHVCyPKcB${W;2SgI230hWx=>zJ`&PnMcvvMrcN}DZ^mdV+3 znqpJW`}14~(sY-g;o1pkr@EEhG5HkUUIJI~mNmb@%a&g*t%^3ETu8X6RJdrpO1t|mcP2ATDl}FGi`U3z_(>5Ga?`pgc_Sb2Ag9`v2;{NmX7e-G73VMT_fcy;UUlG01>zwka#I82G@TO7Gd<(y7SLVVYq_ltu z)(vXn$puldeeWFaJ;repV#o9@F^tQ&=UlU$lu8zjx$kBOAS^q}LjI7!#r=IHr7dGJ z^e#-zPS$Q4yz4e(ugzA{B$)*UFoF!6 zvP!|%u^dzIg7i^xgzQ6oH8gXTZNPDGcBMR_z5@gyB%6y#KZqW1MgNoiHkCMaycloC zrb}#iI$c*~NV%{3Nu)IdWHs;d%ASJ+ei+?x4AGCt)C-^yWGGZ?k+M?)4TM%fJSnp* zH_Y4p5q6z4XkFnoD;Q%=>=p+=Nr=_+n6b4iS`*F!1x`MJRwSD z@wC7l^?Yga>AUW#9d2%kU4%^cw7)4#-0}Wn%lEpZl*kTgV1jbGEzY};Yk&qqkf_xT z!Y7d!x#bj}mF@zxan~9VB!xqSC9uL+bG@v@YJ?bHm2qFNECu9t6@%P44SssIRZiQ7j074jt zlw3{Zsksg>#4*T$^0-4-M_mbF%Gh{J>?e&>Wq_h^?u8;kPmh!#ZY zW>-d0))AcBn}O~aV=w3wDVQiOd!7uXt?M=dyPp0a!c9KMuCu4-af1m)cBW6(lyn;_ z|Dtf(i1>A8Us!V=>Nu>UA00xsRT-5cMfveTr3E+WR`SM+Il;prd7aHEt(iVO2D^Pr zSHsO%?T)v36qFsNZk9ze&g3ig)S$It?o8~GP%RPtQCKk1;XqYGY_XmcZ!9~SlEAv zR`I^nNCA;bYSA1^rHDU*yp39U^7>E;A1|_ICbvJ3v5R&c77a2@sgVs&5Vku|!CJ?o zEi${j#!e_$me-!|)EF1tLh?eYo+tazQVg*LrK3=g_^c&K$c3}j3#&4+KCrzoPHZ$k zE|%_)&t(5h!Suo=?<|7~mokx^YS=keYsrE$8{fp})2a#*`+=STYnsHs1Ts}=z32cns(8K5#2lZpBp{=yjBC;UWJGVw2=klz z3d{^B0y)Zd?+;EJ#>UPQ^1J&Uojb6^{svSds>w*F?p&^5`1?TE6Wd$V-mtFoGv2Vv z40nk+WLQ&-O><8-bvPMdr-l1FtOtql`kjgwf-Nf?VLKzd376U99z^SH5>eGe`H!y7 z9^DoVmr9ZSAtm=;cbjDPZK#6&|K5|cXe8iAxf98iE`0ibEQc}PVR+9i>v?W6b45EI z9X*TW9&^nz|F}FN5nI{obLQE~bb+;HtP&$8cn$e@tRQ#HUoXbhtLWdcHsm5gRy3aK`9J^tjtJ3RfG`?d6v*oejHHk@Sp6;oC)mKB-tV=M9I5rp^+k#k0 zU&Sv3$8Vg#YD=ZM4E-aabrJi7?@NHL*rtuh`W+86mE5jCtP)UQXWd|e2pUjzijQ|-PV~Sq3rc~f{&iPkPJN|> zMz__GGAxG;TxSyV#+83+7#7OX)5Zl`s=dO}62kk`qBI6ZeTEu9wIQGpw}XzC8GS63k3Timg5N)9WkX%!=iV~3(|Dau=*MAXS8a4wz{tq50Rk9(YifGm zhCun|?hM*5@q)ZWEAS+x6O^r1yvwQ-vEvjJV#Q%UFbLS+@I8 zg0248;{ZqVNop}4E_TT>pO$0k2tj`_hFlZ3JE^r{SGZJC5ke<9CSF+4N1{v#GSCPy zqHC7WNpWcD{<8}%KF?W+^#>enn(jz<86A++a~?w}35&8@A(gp_=QSAw zUaRTy(JdtTq)g5?a0pnQz!Bnt0w615#3mfcdVpFJNOJP{%>V_6-{z27hWp)vWtjRh z(Zkcm{V@SEY;l)u?F6Ma*my@kp&jK&8%ho)?~GIsbNGUz7%p5<`C)$2iWeWVxpU;^ z10TUp{SxK@p_-!7W10tQVl<$t%6;n*-xhI4OosQsRo0OZZ=LE&M^JO_#2`Zaq84RCM< z8aGhcuGm|j3=?ms=4Pi}mkv8#>@JHC!3+kzL&L#|j;FF8y!M zg{rwhRWgCsCAha+-b2T~1asuzF+_3=ZAyw|(!MI$wZ`52nmf}dA4TBDu2%h=?4qr~ zp=X9BAWvoXRneVsV%?uChM$YntH2eA!ORfKGU%n!xQ7xf@0B2g$_vnnI6uXvgOTCT ziDxU7@Mv8tA-m~RzC2|!s4j@Sr|Y(2Zv~vwH=%~*#n-R6>@n}#D=GErIP-eL{>0)Q zC<7qIjE&d{Ny&OE@iu4Tb`~%D%M2-}L@?bVM=W-%W69m)aZmQ^gV)7|njSI#mpPq8 zMo`>x1hqlgmnByOL8hrQowjgLXT>xTOf8MaOUd z`rr%Liekc{WPb4V$r%sYe259qKjeNsi8P_18gd=(5u50TFJpmgtdYeuz?HLk z2Msf;4!6i^@TOpf?En<=y7}tiyTgn3(A@k_3Y{LOW?YY})6KeW(B}P*s7=8ce}@W+ z|JKxarg0?sqO-;-N2!2+L_EbdK%;eKT)4|};Vwi!Ov{#0Xp#FT;AZ_%{7#z=?Zilb zeycL7qZ)8-QDjxo?kDLguJvLs@-bLZCwUlu#g3swtHL0N%e86Z}YYQa4N z6YKFpfiRI1m2pTH>?|Lf@Y#bE zTKN#lmK@OXs**Ge6lFy+94?cgzlK$iz*h}DLZnVo@w4?1$@NO7XbwUJ*VU%IFL;L6 z`s_1-{kUdNLKx5sl}CbJ``xeVFYtNcZbIYD=yZv%G+{&AOkc%4hmp^z7Fc*1P{L3q zl0f%Cd)D^=e~$M=mrW8FlYrT{L(SK?nvEEXAx+_yl5in|9Di0yi~VJNff-uJ@uUZy zg?+}?icZ)_!btDwfY=BxVkezUpLkY08+s>#%1u#u+U*K#v6r#XyzF9uyI&RBdBK1ZZ*+t}R+tT5 zoJO#ITm9yXXU`r#d-jYD+KqMn$G@_k>#`A)!9Jbh8LcPiykMQt=$0}?f=%(n8~<4A zdN6!|E`;W92U8XjxcH4{+a2EQ^y97G_VKnshl1+5dj7IJ+=njzf+rY2;&mLkH=Xdv z&D_!JIY~8B-dCj(PkhxvkkF6{EBTw}orSqU11Ix>(EyERg3%YTnm|z}5DR5xO zTK-4*Wl9vEFivZ*G`cFZWuRCW4+hn#EHSoB}=!5Yi48Nz2ATee(ZiedMVtvuHFzO{RDR@mU@dU|wA^+l68nqIH*AoRnzpLLm*)r763^KjwL2(yh@7fZnW=BI1Pkv(DnW>EX_o73<&$js?%_{*ss&4 z7T?b|BT6!uu1hqpvyyyMU8U~qLUOQ1QxV^YlkgUtEgK-Gqp759{tu)p2J4a~FCpvc zZ#=BKOE$-0pLrVyWIPd(tXl;OZJ~8pU1pX?)=Fy93jD>#V}nSLtHZ6S)TVZ&6V>jz zX|Mi&QOngu{RIkJgo3jpVcL`RpBcV(35v7xJ06xCcPlqy)gYX0URMx|pIr2A z^a9=m2;e|BI|H>@g#zIabM>Vsb>z&!JPFV+uoFCtAQl>TUO>wN)sNI7ZqPB{5yc?y zbYSN4_PcY*cZ>Jjzz)+3Q#W0KH?hSYe-{*9)@MkPM?cDZhU`YkRVpz}Fi=2RB9AlP zyP3L7jpIK2|7bfSF2BC5YAqgmPE$Pw)EYAh> zGr_Blx{m->qO|-&J7k)5x@&h7VEiYkczJgij$Pcdx=0r>Y(lzjReC%1?M%d@yG!Jp)7^$FB$=%5M6P0%mYh~2g;01w!yqS) z+bdW->)_etu*28VgW;gAk!*kk(|x|qgW{v`|10Z%)h%c2UcKI7b2+K%pn5MasLx>w zWJPT=ydmD;ix-0IZ~gjYg2pD^f%44OG3sOstYR6}Ko)nk;F^0J&Oqchzo$p#myq?A z!gw?`e@bNFt^o-`X{Ksagmv1_;?^J}HTbVWBbSdr=b%&b3xYh3xhaI^4|Y9QoOvK) zBQ{yLPWy4nrg)>{Q^M{>q%=+9slVBL1WqXI4+4-MqaHn- zy)6~LQ~3*#=Z;;1rvHD)`?lq}jw8!o!Ar+T5dtNvyX^>f#3*D+9p0H)~Qm>-^X$*jt%+8cnnXXa&IY>EW-u3eX`%#|xw;ySUGJdu=Wzm!7~-^MWg z!>#n>q4URLFITDa%uuyhi9<4xhFmdlmw%!}>Oa>ONzLlM2D>$t3JHLX<1;!+6#=e0 zw#4cE@sy9` zt6G5dYe)<3Mx@sr^^T+3-D8D~eA~5!T1{g^u4a3KoH8uy9)}gCj+vrZ!oHMUsztz>h zMAjNz>*Z0D>{jl^f7#433g()b+dHAxXD1yDszGNDwHe<@o|+)s!VPHYD3w^$5}R1B zXfN;bCfouWn)8QiSO|Kogih>63gxrpu>TPt1~C;;==e8LV^3uGlFd%@*Xne#G*nqB z>|slg5@ue~2H! zv%0|MstSDwB4|1~>KPJYT;(9m5P$M%#xSnklX8EQNxeZ}i|-}{rq!YkRb|VJ{4id( z-vqbL)fg|24bM;F%o$E7`&)1_Mye%EMr&X9fB8M-?f-@w;o^An*b7V6yOWPfWi9p& zeHPW?8dKUV#=TqKL8s`F5K|@Ma9`OYLZFZO2`+gJR>D=R(B~B%kqm`IAJPy_EFFG1 zkDll$V;nZH$M_x5(>TkZw9&|hj#s@n`2%Q-O=pLg;_g@_4DqBAERI0!(2243w`q#& zN5ydtcIi_hv*}<*!()k)Q4?Mqza)ckat7TEsro>o2q%JZYr6m0%66W=_(|5@Np=2~j#Zl^F53zDEHgDcD8KuxoJNy;rD zIkiX(t`!XqAt4g z7KOuS`foD0)b?7ush6qwJ0GG8c+6ybGYge|Dgz5d74QNhst7)A6=d1=A4U412RXjx z26!B^&k+;Bk;8uD=Re#wuR^|tormSw+tGU(7d%Z(=$F>xe8V^pq^B(f18|qRI0$)K zVF;SZy6Dp$QEwK`^Myy@v`KTAvCa`21%ZAjUDsCFsmt!=aGKML8ie$bTD19PHeSg- zYc4YDVo;u?jB2EGs@+*WpS!;rcvjQm0T6^~7+`wea6fRL2t~q9e0>FBco-*m>eS`D z0QVCwg)bMPl3ryu-g|5WC~#vN0zx7?m#QzSv}ZU0Xek~>;y@8ZwQ@`Z&C1HEZSQk3 zD~pWl9o9v)j1{7i5i={<$*%po`FWeM&ND$ipf{QAeqP&6(g*eZzTyoCEiU=@=~X*+ zQOy*Zl)-sGhfN;g`?u&z(*BD(An0R>7^$CehNcWwoq}xElya>AY%VW0Q}UbJwSK!} zw79?OL(wLHO{5KkVbkE>sGJAgzaY>wn}Bsp@akHg zRh_bFOx>40rn_y*8C~J<%ZAV+aPdwy+8cKU=|%`cOP}xQkd=<*IFQIZkaVciC90CX zvi~+w+vo&fXJCAr=>bpdK%sc8(ff$R$OKqO)-UanJv#c4(saH&${~#rVRG{>nj{5h z@KoKcwyyTWi9}vyD_d)w@4>=9`Q)dU-!q?ng8wJ{gkeyOVw6dc&-|EPM?g8UM(bxs zbZ4xq*Tuq(lElPvv^*FxJJD8}O7%+vIM}iaww>nIoNJbw6cwH?R0rYv;r#9j$`EWu z-nB1z-;>ov(kj3>G#8gEcy)UkgnUrrtVf8LKK*9K(I|@Lm&R3uCKBzF+iy4$9}!77 zK2z60d|^+&V2!W@xSH;0wJ@X)=s{USbp_tz!jN2<*kX_?#R_EX^Zv*N<~w*hmLz2R zF7?`}fCh)bhX7rBb?C#eV6^az@bq%(crWpS7$|Q1lt-D+_yN>OAaMomurAr?n<)Qx zyrSg%(s$f|mSToavxb5&5Nsy=&1~@y)q)C36n17SxbY?6A7dm}R+~#)gr+d z{vIFg`gP^HG2U)DTh?YDW6#TEP*-?=gr`0S7JJtNErVKQ2fJ0SV~RlO@z@pUvHa$Q z9m1h)B7{ttVO~SyCt7z=&ehSYmAlsw0SiB{?-Ai)l{i;Jon-bktzAu9>6Gs7o|4(D zC^V4!@gZ4V#mP<4O&!$rlO07 zzjtlEmP6FnZ+&oNnkijH)W)=JWDruhAs}h71vx_P|FH>O-#4uJ?44d)7|%^AyHvoE zJmgj9rHVr<`XMz=ED1A)_cVmVxdiUq=avrZC%(jg)>ciXSPxAtw?t&m{-O&3}O+ z^m`nH7>1DccOY=lYkH1S;2*4cUJ|KlZa#a5Wzf7B+ePPwmE6#g@)!eDMJ93p9pI+l zELxBwZb|{tZ^obnf2>WTz9mCVmFZ3dz5RHn+NhS2#IiZb=iFJLH|T^oc*7hOgo(*4 z+t0D<@HN!IrGyiWlW(~IPl#idXLjIWywiG$JN4)@qAbzm8qqe>4}RBgn-vb6LODh{D+%;0bM zcTLBdLe12XFQYKqxk)gvTgbAM?hu6?$q#OtFXVWVE5^r635R|0PgUae%|> zYyfYLQuFJ`krlR>Tjn`L<{#h`#Yx2KJYOYG-VT0t0cgiWIjt>_u>!}P1&EkCMLYP} z=tdyF-z3fwl@K6XcHP&^yP5&Q3MfH7-hkQ9i-QlQP4I)Vq&KO=E>P4yZ~&2 zAD#xRJ<_?ArVE&j!O~4hID~W@ z&LwQ{tjm18kjiw<2emcggJ~H;jOomE@p_?^aAJl4FeBS#1N4)j8A>KlOG+46(rwOw zI)XV)_tovg6{`BVFru7+!A21#a!ofNfY9440;$=Hay|B&_*6@*(UU>ZCFB|jqVD(O zrsEt%3}9~oggSYX?MD{;XLM4SCbZnRK`RoqxX}c-W)@{~ppn?SL`zTX^chqj7~y|O zML1x6KxU8D9c;40jhPpzC$~qSKM3SiI4+;$_Nr;633Bzm6W{`IQm(ls>h6oWAJ9{f zl|n;S;fg(7E;#~Tp~^e(r)|~G!2=w24k*eGE~dnTFAg{4YjT9VByiQzTNXh7H^TQ( z6dH@&#OP1HJqY~pyb@e*wd78Fyg$4H2|EBqCT22(BJRsKW6%G z?9*!$0jNUoNQnBGu1}c-VE2hvM`vl3H+J07@_d=QGZ?Cd*S z>+y5wC&?bVxL{bq4l>E;=LVxg#&Ezd*1insV8pR$66Re1pff$?3Jp-`0HOzcP8~&1 zG~E!uMaHQliK33<847zMFT>!1=WYLscVMXx?Bavu258t1*IHg95`CzvU3ZBSZsi-m zaEIHgJ0?sV9NO;n5A)f3d}P>N$J>vnoxEc=8QaCz4kdJT%&D9mBuu|a0t+g^NowF{ z(XeP`+ejzf!4Z-&>lwzN!flx^>dV+3#>mazokh53AP%$tg!Kik?s&1HuQ+q6fXF_{ zBqPiZlh>~A;#Q)uTK(PS;b-zh?MgeX2RDu?(bi<Hw6BMZE7bs{tXG{{n9>()D z&3xSc=|o>mu(p|ju`}H!MPUm$v`p7vy3A&zB_V;h$`?9^ocB0Y1=5_h9mp${70nDq z?%%FaS3$jX!xv8m2D0zDp=Y1^Iv52HrxBytkLdcfI0u_c(LmxeSG6bmlFtYM5S}O@ zlDt6i9|w}TAN$4b6=FZ73e_MfxvgRZCCN`NKmFv(Rb^@0r*roi69O50)6%^oVa9i$ z>_%5oDYNV%*gYywzg-iAj1&R?a~A{k_M*pOQzeq5-J&Rkj`)CFOdPH~*s`V85I^HP zL{`X_u^0fnt85rC@TRz%m%Dgqwmwo3xtqxuwPV3Qr4y&ow)S%@7^bL6a30ItY=n8= za7B8tSb&5XW#Q;z+lR&{t7FrNq2HHIA!8u;B)BNHJi3ZKCFGMo&9LfxIGv=`U)F@rlUY<=i78W%iTSy(~a z@r)^2Ty%^Ljf~l5w$DnmfNC7u)GORYOdB9;?KY(xVFCpDc9yJ3L*MMhfp{00Y%*`P zqD)9vdr*lQ%lXulO`q7x?_VqDrvs7&VI!Gix_|4T0meo91Nm!ZupGa$Z5H?KNI(8h z#u>Ut1OKq6?;DHfT<#qX&XsAPQ8O4U^_Da*HPQS?eGLc7;vQBjtL_>bQt+O*q}@$^ z-a$yL4oEIdd#iD5_(jqqJ-cb?yG`B?RtimLu=lN=Jk{TTmQ$^0+xetSe3p%DsgJ@v#3fD^$h$r~`u~ z#t-K3vBjXY-M)a0?v*1pi=bOT=~{9LaL_<2V*VCSQRPQdt>s2`PeIlwjAEwvX?hL# z^5lA4_O94>2l^9kW-L*AIf0_w0I{nckB&pe7v^L+JqN}oaT2BeMwdi0OWa!Etkji1 zKwA0hbEaW1(d0BvV5OZvcu;WhcyL3xm)|EGWe0=EKxqup@*+2VHJ3;Dfk4 z2$BB^@DYo^`XLfaKSa42CkpCX zEK1(aL=*2e-3-%q!K51wydytHyw9_g(QQ_j7q`(ht7xyd$fgNL0JVRj#Yo4uM7EpJ z=toGn20EcEB<9ObW)LdtrkjRPKgkTk>;%`^727fn9gF zV58Eyw>4)ohbsBXfEsQi?c4XYdS;4u+LcJ|1u5*ToDlOehxz3YJ;cVjcn?#g#H}yw zy5`S>eA90xGO~3Cbg`7yIZ339y`7-yd9Q3eGnKMo{|-qOSrPe1@Xq>XEm9ywBA+`7 zG5HI1fx;nS20w+}L}}{D^v`zATC1KyD63Nzy(l<@A%qPtn;}EAP&aVDGqLBMv6 zEV~SAt;GsS|Jo^s6)9No$+xRjBvm!2np1M0l|;Q-J829Qp?Ua^QdMIPtUF{Pgg&#q z+3b#T9+Rz?6##tQSf=2+<}Dk`qE*6s=64s7yiNR6cV?*PDk7&L z+y3>pFTd7G7#PLpeqd!d{(pfXI~wYypyh#E-1Z3qBcD0haJW5L`422x;jHe;8K}p6 z+sTf)vx!*fkHk8duJQ;s2?(vro7f7j`u+lYq~6;ae3eRSai0;`Xo#!6d|VlF7@v~} zg*z5uFD|&3CEa;)KIS^@jy2%9$62%vBuP_&II^;Av{4L*F>z#QpFOHIN0B4L>O(z1 zD$5!XF+NDLZ03jnJ3z$0yWfTg;qc4V&BG0R%gE^3{g)eS;b4geBRcORhp9v*=R)E~%LE#C?aY#pG~lUE2l)ZzR5tNa^e4qs%J0hLZqy5%(ci zj-ID_79;ARa{x_zse6Tc;_MPu>jrN`O5shq!Y0vQy<-vCuDVvj;*0+>%{xa0!rg=6lO7UB(ss`;>XM$q;7&=es z#eXoc;+WwdGG798)*+_@JD8Gbpybu4lGu$K!8ANTv4Wh85DMuko`d=v55qlNz`Sde zeF3J8d)dmXYmS)5cisj(Csg` z696}H)cS09O;C`XIkwP_^E2?F2p%Q+B6cgIg9i|4`N_4Gty!z!;=O)g(bckXYu`pp zAFz}AD2rhYe56xS9)Zt9P5!wwpCn!;hmhXj*Vz&-x zTV&25`{XY$@-?WdRKW)*jqqbZ>V}{jjS^Ygep28b@Le8#BAv(faY7u7@dY5jSk+Pt zJV}Zlhd|@kOd>-b<+s_h0~CdGY;Y_Vqw?A$Gxa}5r7?+7q5F|TQvZI^rM4(F9PT*f z%TQPEMOfsMe2c6dRQWQ(p6ZfR|GGgBLmnoWIH-ie2ag3y; zmOdDa2n8Hju83^b$J@ir)%j;Q7}Oi;xxiAun<Bx_+9~0>t#B;uYok^NzBu`Q8Zk?sopp{HM{PuLZ)?Uri|hj$&IxcFhsAC>2Vf{L zk&=b8B8uWxLj=TAA+v&CVqQ+{VmJnFl0sB+6WZ@p@v7{{rP&_dh^a`y!+k`X^eL;} z8_t8V#Jn-*DBQ=M^ln;^?ZE(S1SzNxqgDy&>-Zs8nSWAY!V? zDIOo#i-V>QOX!w44{6ck)3=8Zog?t)A{AVkd!FMKM!ys)hakVfrJx(hNL%4ZYAwXxmWxTH4hkW)JCJ@Q^^nfl z(Bmpx&2WhQUzM z6IXKE|9S~l8Z65Xm(&##6X;^OrvXI4`9V}+9v2UBGh#UrvKS?$f~Ch*MKdUlPq$7R zR&Ud6_=ax$(1B?PPH5pVZ;wZnH`zTEh2Cof(KFZHc+F@P(iS z=nl~z=6Y*djqpnN;J-awV+kFy@dWLiGSoJj+9Q=X*?P9sv}1|1mtgP+PVtJvgR)T! z*xgriLkEjQiAcepYe=a)D*(FPRBe;PWp6G(Cs@P>^J1yr?Yi z_2k6&PTLU}>j%Vp1?Fu90J;Jh(S5dI-|P-zz0?UB=egDx(wVX(Z69jbC*`Ds+mS+z z-4>(-F&z>noXcS3bq3LA=W{dYyaHtWykyAX;`olvDJ}x$Xg1v=da*_;dX$4iXUKlh zX^^N}H=^(BWr?7nok)T9)sb zkB)gVa0*FIqNvKwr-io^-}d-O<<7V>IpcUZJC}hNw`%fn!G`wb93jyd9W{9qcRvHe zbgMa@wORTEp%!w7w}E*Y`y%CF^m&tNc?Cm+3DMGLCCfx?U&BW0Eg))SUmLOvbvFxB z;0}bp*Lpg^&DY;k73K{%udblYH|>(ZRr?3=Y!Z?5d>!C-AE5w_G8K5Bj9*D*W~B-} z>C5EEf(H$D-pP-MbFSxmMyQj|im3c?T*RuPpdo>G~j6$v{E@ z7{z&;N1gZcc=c~y5#@aKiHT`P-_aA)aE5;?6hZU{wgFPOu0wr$b_~)Po(1Z9l+H7+ z{~nzW;W;5`WrQ;apI%ye=_f7Mqb2N0TD>v4uNLO}bjpW`yf$;^NUO zkWoFpJGF&9!@Y@wm+(9O9Bw{`^2>_q?0vawPu7L?sL32=(RS23HoLw|`133Zf2y^T z0L07G$h^Q{BYafIrITG&XVr&l~Bfex`Wp?pjPTsAX=zO z9d_kb#SN(+2-QjEd|#tftQ8zg)4sf%<*@ta z9yI~Z^&+8xz=3~#Mjn#O(c7am2SnHXYb*2Uyh#h9J7uF=n%1{F)3k!hsY6N`7#8~t z;ock>Saed5U#Ls$o27M4Xt|23 zmVTs>D@Ge_plyiC2d!40_;a~L7_3mQNX1Y?a+U9Isu#}lMe$`ozJd|2P*2_v-k>D8 zvVBqu^X>ZTr_GxPr$x%Du9V;T@+nuWUCkV`H7*rBNs5TDdeSWTvvA1E(&Se@5tFW$GU)MdluBB{n6YwZ_R&;R7MU(5!L~1)f84!r zniEngKZx#!iR(uz@1fwZUYt5ke!{24F=Ju}<-#IiBD(&sIIhpSVD8|qbD6=#XDLCq zzj5y@b1~jKTW)U=r+egjfdha&ta$$T&NeGd6rLNixUrmK2@|1+|_Jq%5feHe`00TAowTYZnW1WD7$HePS7070l*#yqjIxUUJ10iA0yH(8Lo91<*5l#0Fh~$YY78 z>#E*d;?yhe(>u1nAi*R8wjpZGOPpAZ#c$-1U`HMBf)8|~W!}gf*Tz8CF4mX|>G6*M zat*Z+PSBg{bk)!H|oj%C;%_r(ILRm#n8-bC|}%)pFr9KkmEQa{Rxr z7N5yf;Dr3+j>T9$`TvB)81(aJ7tUDhp3vcF7bxtwOUX;HDhx_5Z{q*1nGF6^wka1*@(cRJCX9}=PNBH_9 zIXp@QBqZyC5uKC#F8q$@Bp46NjpUuXb7WmB+!%NF%f|YFpajqiV4RVcMQm0jn@AYv zB%VE7T`L-?(l%CZU7is+sFBYbzNqVI$X``WQrFeUlV4-E?X*J)&lr*te6QxhZVp6G zaG$+~YXL7B?l+Vw{VfIhDq8O>8?{7)x%xt`*OdjM&|G4 z<16mEdP`N3CSo^J)m0kh;*$*DkZ2EDY7<{!sTYSGKP^8F_OhjbN|M|q7+6F-EWduP_%JH^eXX~v1nTSr=6W{5hNTJ zwdf;hR&VV>NnW_%5^`(VOmW_`w@7IDkJeIYtoHyNaYixqy0B6t%vBm@YRxy%verEt zQi)*OzTwomu%P;U|6Dy(w+0~uK66wuX=D~@KD#Ef*Y}NXTCbf_Zz>&Oy6iAhU|1

ekHSK6;{D>`joW1@$o8aCcDoOY_nnMdlkU+uMk7Zcn>?zzC!NHctK?;!uZiVSn^chhO z{^I1%lphKgVfjgRDP}!OVy(Nw?h6Ob# zlSDxmD!I=P5;1NdY$oY!X52oDH9n%XWP7B9f|td4jY{_*h^05|pHc6MfPya|RCI1A z7}iY&Nos=F&V18KD3lu-vFjA~t*f%RBI%BETS)E1E@JTtJF{&ll?VrH20CY#-u-)7 z2eA0nOK7plRl$-we=4GKG5V)w+_jqf;R~GT7n~Nc@UL=~L;i$ON;;4$hN6l>B=@DH z(F8Hz;;`I-c}RvSc0F5vlA=8mrku;RWy$T@S0!?+kgfv#20jO22uL}NnkBkcTv!E9 z_W9->S6c0G4#7j-zym>eoOuxgvd>npHDWoRpOzHL<{StrTKwPt0m9JTh3kW5TVGyN zeKgfae!pC<<((0JwYJ9U%EW?%lmD2Xnl0YDKJ&9GGuG2oyBeSLYP4sMv-CVTT&N!^ zEE!Ff72CN%x#&1y3|Ddc4Uk<|_utCj3EGA22Unidly{t|7Sem{9q9WsIJ zMf?n)=KJ#(3Y2lVArPFcCk^0eCaM@KlL7ro>g~~ai=u-&9Zl5(@nSO3ng z@C^yf&js{w23c8Gg7=*r(sH`S5e!6(p5-Vun?oHtvbm=qFVCh4ot|s!B2P4&M%m;; z%O@#Mk*m3^-d|9-s$|XUlkYhpL9P1>tJ6}52bz*~x4HX0C;$;B7A!XdKLrkm zg>LU$xrh~kM}*wmx|qDB9dY2Pn9G!;Zhu*I>&#VFt@hs_@bhbiur5=Nw2Z0i5hm;4HiB;)4?qTc=8C*O85d}kKnL8;s zFzbgBg=>(3_2X$InoFxL#VGw`iF8wbEr#5ma}+Idkr7GatyCZ2Nq<0ywM_`YI1+&W zymst{MVn3XddVElt*)RO1y-nRxK>GP@w@B-DWwbDWONN%gF)5DG_foS<4_j^g5A8Y zqUj(d;?UWll?5qHOt3wvW+#5t&y%-H26fc&)5!dVDi zhf;1mk!vP#{G#b%$zFzxGUl(7+Sl!=zHTha(tF}K= z0B{u%TOcdJILOhO+>Pk}SLQlsYnwEQR%<~|tjO$gpEb=P*Ve(fL_|q{|B}=VAbG-K z0iew8Aq|T`j06>1TL)DnH;hLu41c5+kt+CzG;U^#ny>-s= z*ubO|q;~Qcw!Yk*uv=D3-$h7prTyA7#QlsP51gv|Ejni5`sibNHi`%q#Y1T%iuC2y z3y!zP8+T6WhY+SnCa{uCJ4eKoUL~@!ru?jSW>iZxIb0k6mew5yoHR{-xBl6@Sb?I1 zC{U_&xhn6-JG5G!%}hIG+_(` zW@I89I(Oyz2)+a2Z1QBBHl&&f15wUIILKD_!8*aF+2-*v)?dUS@VADDX8cG}1CS6` z!V(t&)6KjPEX?9#TSj+&lM42a;WrT;(vuZF#!eyiKS+g0_5zsQ7 zul}K}LJZa5T#2@LlQ?7JAgI?}^3%|yIgxTqDvD4PW$E%MfEAys5V=d*>Y{9IopFc$ z7|7U5HctWI>}XV|eDsvTUC>{*nDB4V_Z7?n`i>~su$Rewi_L%qV}zLhj!I#|8IdR4 zggFC8TdjOrUm6t_QR1S5io$ho5Zqrg4}=k`os8u5>K$Zl>ubn?Qh!n3*ca)MI zu226&qM-8?biVsPxLzb~&FkY4UM#!fvM?TSSo0WGPXH5g`QptB61Z!BQJ8~9I#=}` z;)_f2MX8YH@_H4?v@Y}QN-k)oPhsNd)$zA8$0VPbxsers zDSRuxV<#<{xw(cNrK2Nh!Ye3=xC6|@WJ~p>&96_Qfe2od4^rU_d8D0YyDOn8woTzK z(IBQDAi!X-2t!K@GuO8{jLRneHk~B78`!+fYl<1*PAXgD;r8r`)$*!yZQVk%?IdDV ze&0s#ItKsz?sca}YLJK+qVz}lLCBS+^$I2>U-NJ;PDuDDgNn>-FE%h^S)|YktR9n0 z<_<}CPMV*5^4-_pd};;~GJJ@X9~?6q|KzoB@|!QgiI0|dRDn^Ugw^UL@BFc=_Ei!m z6JW1#I$%J%h(l(eiU1Dj##R_-`@-&kbmd+SIy7QSv<6SWO-rfZ$BTr)AXdFzH8NFK})S4=&2Mkq?# zO`(m|wQk?gwqZtR)Tk3~AY(ZImigc?V3AwqrrQdQwq9;>y(MYqb{m?jW|2EbNsTm? zl-jG>GhT;!1{>v(E8>orM0(1tLlm3;;y=1dX2M1Y6w$a^Vk+ALEu{hfdo-)pg)P4^u zP&k1$DVb^&rndNXk-v z_Th$|-JyeE=_%*u=~=6@n#-F!B)9=AbLbr%L%!a|1nI+zBZ5{uYODn*0aaKf35J#k z);f2a@#yzyFIC9a!xtZ4e|H>^ocOSS(xiyVf9%_O9sgcLDVzme4H%Wc>H)czIwt|V zq)bEE(&!}$d_^Xsz+PrS8Nf}0Q*Hi6eS6p)f8ArFeiEIEanyN=Zs``^VZOCWgpN_P zZlKh{U+|45)l18!G=PL~gDDQCm$Bz8Av~X0b2xAGFuolV357bN`d=mTWV2Dy)J-i!~ac%7LY-BW8N@!iQ_ z18k><6?rX#5)>@g%e2SGngf2zf{rS$2cNqL<<~oeP+8#1N?DF^IZ=wGT!Sk66n?^l zg61sPev_D0v1$AJbAvb2ud)g??s@N*_HbS~K+RZh1U4$=ark0nY|K-dFe^@Ut7_gk zT}nmCJ6FGKZbLk}=L>f83ekUevMK3mZzR$N!Hj~AwUmIJm7OEiIT8`ow>gO;#U7)% z3Ue&59hpx#49;x`3-LrPVEeaOrrUPz*&xoR+kUfa-&ElHqy*&x?EY!17a%W3)=rI~g6wB7Nehoxr0Td=M?!4pIXAFZ_Ico1c!^qj{sn9EBX0Il;*-)yhO)>D%a0 zjV81l4~AYvkC_OZ8QB$KX5;Po%75*;!7QA{XENU|<{S!EBKN6Zf>SZM3$CCd_OS6X z>hiz8VI?{Mi1aK2^Y@W!9vIlsEaA=uVxzo5Y@NNNh>+@uUx~@s91~}su{U3=hQh|& zFMoM^K$N8Jr@;hpt2D>y?oWq&GXTYCrDr;Fed{_oUMm)Wl_hAhmHl%p_g1~rt^M1} zgdY)cdWW60C;bp3&xYvHPFuWmmt3(d zJz;$+Q33Um%)h?4P}#zkcU4jD4JJU(IlS%7stX_*(@bwg1po3o7aHi!#NlD@9*&Pi z5uz*(ybQQRPQ7Gz470~>&_@eXtt6Q)@aY!mxZ^y4d3(@i?1&JACk3tDC>>>eDo&!J zxTGH7dos}AlI%Q+N%zv(D*{CLbJ%M8(7st1cVHmd2qg=!Y#nIlvW2vU)sj<_2UE%p zH-<+)rAcEYVxBcc3AX5yBVA+IAv_nwmp(DYIm0=7KqHtiXL41+=;%S0)6bh*IKOfH zhRhU^^23dy(?qz(4onD`Xg{1ie1wQ_3`3{lFsD2@7<0sq6~cW&sp^)r2%l=SVbR7N9ch|4 z*^fA~>g~Szm9?`6<=ql#nEH4K6iXt&;>mS60;Rio*;lNq$X;UC@)~N!CHfm_XXU|K zT!NBS#W`1roy;#B4@+xdWd#+KDlRHWEcv&awZL(B5}@(?r?RnW;ecx z5)auGsX=aEI5jP{lewdTSd3eH1fai?XL=Vy{)WM#DMpmBvt(EZXsQi5^}7 zSO>9y%MTQHXn|N$kcx5($kCf|SVzPJ&9Gb@PmEkQ_S9l!yKWc0Dyc{yJJ8Xp%$l{- zI+bIn;c$CExn|6+wgxA=gLo}Lp)Eb|;_sFRe+R<3J#XaTt6E`}?Cs8uG_3fmDa;Mu zjdT@ATe};FLV8n=i4!hhSGISd@t_0)_D-XyXe*H3M8`hEcLp_sZ#30=;JZk?qN>2k`^d)V+s5)62-TB>2z0$w=>cKBlwi1@NUD) z*+hg|a&RoviHI&-RZLAcQO_fNZq?$J_2W!LcNFquVprP61QKT1m#XiNST2J0#mfER znFz{%1?TA8^)bwxH}HQ3{vgm)oR=WQjF8B|b*f`;jtyjFSs+SHn?r<4)!V#a5C1=+ zBxS0*OBSbEnR&V++4fSXGvc4>&lAM&@J*v01zVw#2UwdIzGP*6$%=KZmCu5TUwG8S z{w^KboSbOg+2$ShN37~9MjYiqNVd8`8p}rH`#Q{p;bPLF%lUp}`@}7mb5{0sH^x0_ z-;?XZhxDDB0O42jkiR)f$dOe)ZCL3^q`9me?XwoZ%O#(5l?rDmH9Q(#46|Ro{c($x zT*k?%Ra<~QOr;A*1blymihFAu4p<1-UJ}n&P^#Dl#-EhM7W@=Vx8;prlmFgw{GBz`h2Sh-|64DBiynRHbHyn~S%ei@xg#NIx>{-kD7S2G?lzE5s<)zt*X*kgEaw{k(#4537K<+-o%;%CxbkpgtJ(pACSLy(pM)OI}=WEbHk?K zPgp%w%r;vj)Q^=}u?PB&=UGDR1at4VUcNnCzkcqSPcXOZ=2dm(zK^F0n?~VJmRzMB zY}Wv*C>8@{9UsUZ;N`lcgwhYIsit5fI9a@*VS70}twBZ(@Iu8kI-L#-yG=;phI9yj z#a4{--D};GiMb)2V~T0Dp&NG&`7&7iR>KBHoV9gcuf`+H9U2g$z64t!`G5?Iv3a^E zWd4KvX~2AHXws>_`@?8@Fec^|I!CMjrZ*G9PDLjM`}8%c=Rflf>W`qj6Z zKNAnb4~k~e)eqravEQ&iQr@iS7Sl)OD&p&#E+3BQ(@>nqzk`IvbB{xB;LJ_R?DFSA z^hAt<&1PY3^z8WYyFa1CIQyIR>A}wBo`o+9FZV`CJ(6|(tNHxkMMhM!J-P!G-QFHm ziu(w=0O=&wzlK}X{9@KN1S_bMu{$AROrsueKi+_$d;M{HB;~Hkd#`s@P=Zgu%GP_r zyfLMpzdG4+Za1_+P@CL4cU+xglRoTad|_|r-zdXl8;mBVUY^ALoLR3FuxFy>mV$ip z2VL;L5k&>WIt$kacp%(l z(mw!gU74LdXIG68|6 z;cceYL8ER&)`fKnn-?550R28NgCQ`18dNuIaqtrNo}7t!b8As!a<;cv(A6rdlK6lh zBr#}=EvZDGy8#Zl#BCf&&su!u|Nd9i`#&OA!CJ#hwu|8z!qi-cLU-HuDoD;)E0N>@ z=+B!v&9P!bqefVsQI?G=lh~eDGKc)__F3+U zjGu*Qzyk!d@2o0<8-T{bo|bliC4WRAhkK>&4o2NGhWfkGiVH^SsHhB?fq4-=nbd0j zb_G#)kP_a#guL31w#@-lUvz17p8DmdX&{u(Yll$%tB`UwifE{){qYYp`E*YUMPYsXCIr0mq0ewF85sc&JH1pvMEmz@vIog96g~tV^;EvSk zhbS!#%8i~PqrLHpHZElU{jN1ZtMIA~c%HGzT;Vz_%I9&Jbc$QeVg4EoL8cubEz@9z z1n`4ZpfoE#be8(M2cL`86c+mmr>nJ=2usQsoUwCa81?S!3%7L4?yxm0^2Bf_`+^BJ z(m3gjinYVEWBy4uhe};R!?0&J4S7#~P?f=Xd+oS=?1{uYx$cF2jW*sy06W_4YVo3I zcPQVros6Qbl78Xj^3#?#Gl{U+`+o8f1yE0ev#|+s#m!Gq)tC-u45FUg@C~*zfMT?C zv#So0qUtty*>)-hOR9;m%L}pkl&tG`8KVY=T?aLn!Sa2ru27qwRT}`-m(`9>#l}eu z&&?;ASBL9}$plY8;@P7nC7ztdU=fDHtmVbrh}g?e(-;Wcd9tVU<|_2BkVG(7D_yeS z%g)1C%O@Y-2kQPzz^*O09=v=VF%FUvXzylI6A;;!D-DBB(k~5W1cma}9CGIFOO ziHJQ5IgYPRp4h)_+|0Y_aKtYzJeCyyACz$l6T;PIZGK%qCw-=IM4S1`H4hLG-p%oh zvWb>2Jo)4rBsYbR6l=Ui8$j?k*_2X*{!i^l0IVG|e}RuC{j?HGLPbFzo)U?IVLc0) zTD3^uiO`wjL7|{j03B@?OiUvT|8+y@ZEE1bT;Og1VcAICk~OI7pl50_${T2*zcDqG zud}?28z_1Q`=oAvlV*z_t`%VHkWm`b>CrTON%uOyW~^c~mQz9r(RXY+v&PEbI0|Dz z)#z7@l=w7&48FA??VaQE$on5bP+Tl%@0F+K?(iD4fcTK)Jzp$< z%2a~->;Q;kX)+`=aPcs-NY=&1XiK1F4qhkV`7V~!NlVA?$~Y>}5lDep1k?g4PhOy?gj(SAL7{m*> zCUSor&gxh2KV5{YbRJKN<(yr~bsdFp~fIv&ZgRa6>`>ETR+~ z#X2h31&=QB+EeS~lTZHm!>5LMnNP4*V$BvxuVYdQ%qC9YnzoMqz6Ln zH=;5zueLYRAAblmuz=@5UuE~=C~pu?hM$ArE=-F4%0S}sWYs-Gov-&c9pM{I3?|CI zZj}Md3CEHZxWq68dvxhKuacP~a}GGhN#Q3qcx2$J97zbvA)eW^Lqsw5z@=Kqyq6e0 z`9y_i;4z#XF5UnEd-apUwNE#F_T5)4jHTP-?J0W*T_5k*jlIK#&o&6u4~_l>=-hQ` z2pZb87ZPSPq)PDa26#TD&f$1v>W{fC{C3_&z&ovkBoEe&lC-WE#+b4Ns1d0t9Vb>$9VJJpCTwCr_{R@>V z#e`vefBeD9=O~&Ht%Yp2_b7N=hxAJ3i|g9cM4A0KyS)E^Gy#u;Y&UU(dA|o@iGOz! zboTJNsaz9!N*m1qIubhq@pzCv#?c_XK{5x?x(bd6LPT;m=}Pgb+yh)c>LjGJdhag0 zv%$Bb!r3x%1_A%7m7pT>18@q~4W-w^M3KI8?=S*$&V~4VZ_4mY)SemaXZ0`R!i>x8 zYVsq6zh%y%0U~?37%F1ySrG+(>as*nI;=mIwup7w#BDFJ9P_r%usan-!^DGO^uIZ~ zww*YVB>Ha2|4>gWESZ}b+cRG6TI~jVdgK8F*wXBa#nndk&@2sN{I>tFf4E<==bVVh z%&N=+W}b|pyDBRyGcw}Di4*mtChC#Rgie|_Hw%_@F1pR46ZFy>=)F0}n9X$7Ow@jN zVLDC^1f>a+sA|j;7M6{{&U&+1Kg{@=ZJRG#BX!4){*nW7R|GaG$a=G>-L|_kjXaVd zw)Q+$w|$!(XAf{0GtALW5YNYFvo@S^6pWAQ_si{P-LtZuUpcr*5{Fh4*WYMDTzos# zCj`^`G;ykzaF1$iArrO43F+xAM7cK<{*20pWLD&Oot#3}7|sCJPakF&ym4VYHVJ>$ zlIkzgx2!H7qIP)ge6NDCqAK|!#pEyQw$Z_UbYXyCR)BRAFzS)fNR z^X{xXFY-K#5+ilF(miVUOiWXZ3J}P}*NB)#PehjJa0S3VI)~yyXdSJ(R)(-zYj*GF zDyk1|M{ZmD0Vy*gZ7BzRsd9;^;q%S;$)SoD=bT1t1Vj(|1*w3!ea7%5jSy6EtQ0PO z4Rt_uV=m?)9t~az)O&fFDZj{*t+-=(9Q3R;EvAKfG!H$f{oc(nL;^<$6qqm!J(cgJ zZVGkl1a(b7=+u564VQ`Uw7-lEXjMW784uXT%bO!SAK?`$*l7=CXp zI+=PH#)A1AC?}xhhIxfCUcY6D3PMeK@>nEl%~)~?V}7{stb(A$jsU7&NANw=z<^l3 zPfSXN`!g(;8t-UX_A$KI-LCaz2^NZGjeuzjk3lP(d)(?;3Y-ypjd5d~sPZr*+i>Dw zmGG6(KBNE!y*b!8rlQH1^z~pT-N9GqJhyQ}n>15kgPxVhEQ7QIZzdPsLnm%|Te-$> z8L@$5;65U3RLx*}ExvH01te-kGSS2`ci(BBh?N~L=yk5uHuS6;eSSh{oYSM>4#JT1 zl|UR2@mlj5oa5knvMOm6>@q4dS)6RmT1)st*LX-!pKf+&xpb7zBY|#ZPlugqh6Xei z9%|JrH%@Y&aD*omkzTsgZq$wh#%|++Jm$bQI*~8;bcb=dJdPaF!bYGz^o0$sK<3MEC_MRFsVh}nrUs+{D zUI`bR;>1rjT5&iNy)KmXrepRiDLP~hjN%`xBG8h2{tT13ryu1|GsML1R3Sm7mj^#F zZF3wlTz+YlGh=3r7rpruUL^LT!(#A?VlSr522(_3|M(&=`a1ea7A;4ZxG+iE-$9Ip zTW7S<_QcVRm63zo{*V^Q`xHzz6vUxv1f6-Ir+AKDi~EAnOnEa_xt=e;^DaoL!V(ND zK7uMML)i06vL9UsEZCzY zWLk9XU8g9ru`c;y@w{04QiCHDMXG}Bt?~|~m*+gWZg!#efLOwpAX&3LH2@8~;@+>b z%UgC^dd-I2#}pCw1`7ZC&wstK#amkB14_e_FS83zcMcQvx|@ER-<+U9@CA-x{LIG7 zwrIPh^OaL{#2~thVDg&Ajwo8X0le`e5>yer?r<%SgyB8pu;~VC;mQB8241*Jl%>fd zwU(fWiAEh{>XO{Rp!WG7a)VP`*z0G<{pA^XlPO zOT9P1M1mTW3W8#4pDy1$98%J&IILkBFn12*UyCo*haL;DcrKNaU8)vF3OeL@BF~aN zte%Z`n%)8oR#BS5lvBwWybCDri0|rW*nkJuS^?;_+P{H&O&JsS<~t3_zfWtS*5d_g z!+4J8Pyxgw!^h=Ts58N8pjrEn*%ovYqZZYfpxoaTSIaE6%s+uKl@ggh$XL9uAjphb z0&-!i?(Nb{$AE`QJNQkmg)Q1@xAh;NdDSYj>l+<-B9Ftg<;FT^a-vhIoM$Qrn7-$g zj4+ydn-aAw%LwUyd)IISZzLbm3j7Snx3d-S4GuW!Go-u$Q`w1l>PENk^1+aL$Xdye zZ2Cbn{!Y9&(mOPlB5>!>4Z`8g(O)XDkQ16Mdq{15tM-Sh6Xga(Kl0(=55j_)EC$zp zBoDP40ecYou@AzK7LJR_7UIP@&RR03NN9)*$>;eT5?e~5YHhV5)ZtohM@}O&iBu99 z(nzHqUZeVxgu_3Bn~$J8Dc1yjBrY35h*|x~b90HjZ7~`t{no3Bl4>|@xcJO4AoF}R z|B7EV`~WI#Eb z?l?=W_;$cvtX{zZgi)DS6FtO;Kq-5Pq28N{&AB~>6VYrgT8Iacz7#2;_x<3|S{WR6 z3%Nou72home&*NlZY{9Zkq%s3<&yeDDX1Y5hAb}V6wVkXOFb3!w+A96!YnOG9zlR% z%IFB`;i?wopiDg3lBU+leal7x%N?Mnl<6nBISmtC$1yz?TInpUj^8ANpMxt1jzST;whc3L>wo!$g zgLd3=IKP2N1Cq@vmM0Nl=Y+c}Mt7ogs70g29UqI$*zutDBvKEP#&t9auESKvW{H-Mnp+UL%yMWB3Vdc> z=R(f0IA}tVLzAZ`TI5)p^OehM-35_k^MVyD;ZEv7%ivPQbD67^)-^Tnb^M~g>e>$Y zNM5AyOlZj{K4)9-1mFmN8YZvg>tP3}joQE_SOTo&hi1c5$Y-!H$?$wTIPR&2gC8^) z%+P(PSu!>vkNoN>kk+0ixGYoaq1bFQE02^I4!f^_(hqtOd2-d<^b>oPtx^s#sv_Jd z`_@%tT8|I!w@emsf7$nlH!Y(LIkI#Zk8;9S4}d#D%LvEfub-i*&0fGC8+68AXQG7{mv~vP7r8;^;yK93zLb z&6a)g1Bk<3UqKe7$tZCoRD^3up6MMYUD732f@l41ILdIr{!+M-+S6k9E*by8Y2me(m(u2wd{NA46p zp&7mQ@O_<{+r=Fq*SC3&;>_l1Es$#Q_alFmQeUq-n#a>W)K>v1t%wES-=g5SbS6?Js{p+)v}P2tX-}uf zs=NGx@qw>~*9Z8Ky|N4P#k^#qlyZy_tl{6J@G8SkvxNS-hPPxe+VLfMKE}#Zm030U z3?G^FFiKqR_0~r6%Bnp^cjimvN5TYztbGcj?t(Nm4J$oir)pUjN{j-Z-FZQn4|9+h%yJE}gCHJpzzu#^vt$p{g`#qT@(Z4fG z|NeZnd270Kzx-Zx{$HWrpZ@w)^f9aS>$h)ZPd|O1ES%B8@hI+~o#4f{Q3Fy z=gIXi{NwxWDqp?5tg4hRS?}UE|HF6rbJyZ*{ue%e^W??Tes$^WZ1wDRY5nWh%&(oV ztJ?VQ@-H{@JDx>PH&6Owq+<~N>C^5lxwr1$h&?C0+UO8}WWr(ng<9W54NNt1=luKE zWi@a89N&*!r^SEdRA`^xck`WuL+x5)o6DM$S?V8VS^Wi`(R%lXh;Nlu@L~12Lf)Qs zzzw-!hYm(f_MOzl=>M-s?CZ+*9Wnx1f$1^t=Bo6xI=9-T2$w``grSPkwbYevWh6gUcVMTk;)#C|_?KYg4zy zw*F5>Qa~^hwm$Dw|0cM=bQd5 zVcPxoj%MzU#_6r|H|>gu`TzMp0|UeV|I7>l-pni_3~US>K)xcwKOvLV-i!=sX>wVV$&L^v9Z&|Ih z@a>FK4gmslH1-{RlE-b9>9OeUzrC5eub!&;U}*Wg&hq)Bq%hBcV z+0A3G=EcuhlJN^qR4!v(EzPTXtJ(SUt3PWVw0$~uXmKu2g#JO-#wD^(m$^j0=RJDk zqprrYNe?bK#+Zj0%J-Eu^FEf(VYX0yBBcGn$KZScd(T-97xpC&lrPoX+QrV%w~&qX zmh~Jp&3_-OHk|rvc|luv`J}phr{&IfG^0N_%G|Y9cTc{(&C~jIa?2mhy4oG}uT}%6 zn|D8ISmji3O4s22jaPn#vby)~hTX~tJk8|4C9mJK_@CmM8ePYj_x^8}Pjh&Gn#aGP z!^y^KilvtR=GnKe3WZ9Z{A6)9Y0~;jJ&LA6e@DKZizsni)UVO{Ei$G( zVY}xe*IwQqrmd!~UXP_XN=ibLP6cu8Fl@RmfseIOhRGGaE#~F3HtqX)o6b?9= z$+|^H%FFCO9H!+et7ou?-POB8Wlq!LoqINKdD@om#wfY`km5lWm&V{LF>Fsf>uGb0_Y9o*lpXZe8fsO%AH2zcw4)jA%XF*7Lb) z-JHy~m8u#4XP13<4nNiwT>C#{i*YaO-Qa|6bsm3T$>-+fDL%Mu;6L|GK=a|IXZHNn zWgDtzEnXZH_jeszY~sgdKP4oleaQTk`R7sA+&a(9)nazj_WalUCk{*dj7+)=i1OE~ z_|lDBVCvUkV_*lfZ~$MoYZ1$b{~4T@7u#Ez_fFl5tvYs!Id(I){MlW)Rf?oqRhN>tR|o~Dv(Wh q4oox{O$_vuiCQBdYtQ6E(hjX30=!v)5eD)lFGCP8$)^f}+A08XGfzzb literal 0 HcmV?d00001