denied party screening best practices by cindy peeters millitech, inc. technology control...

20
Denied Party Screening Denied Party Screening Best Practices Best Practices by Cindy Peeters by Cindy Peeters Millitech, Inc. Millitech, Inc. Technology Control Technology Control Officer/Facility Security Officer/Facility Security Officer Officer

Upload: quintin-hobdy

Post on 30-Mar-2015

221 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Denied Party ScreeningDenied Party ScreeningBest PracticesBest Practicesby Cindy Peeters by Cindy Peeters

Millitech, Inc.Millitech, Inc.Technology Control Technology Control

Officer/Facility Security Officer/Facility Security OfficerOfficer

Page 2: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Screening is the Screening is the foundation of effective foundation of effective

compliancecompliance

Page 3: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Millitech HistoryMillitech History Millitech designs and manufactures Millitech designs and manufactures

millimeter-wave components and systems for millimeter-wave components and systems for both commercial and military applications. both commercial and military applications. Customers include Raytheon, BAE, Lockheed, Customers include Raytheon, BAE, Lockheed, Boeing, Rockwell, and all the other major Boeing, Rockwell, and all the other major defense contractors.defense contractors.

Foreign owned, operate under an SSA so we Foreign owned, operate under an SSA so we can maintain our security clearance.can maintain our security clearance.

We have a large international business and We have a large international business and have many licenses & TAA’s.have many licenses & TAA’s.

Denied party screening is essential in every Denied party screening is essential in every aspect of our business.aspect of our business.

Page 4: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

KNOW YOUR CUSTOMERKNOW YOUR CUSTOMER

U.S. export controls laws and regulations prohibit U.S. export controls laws and regulations prohibit exporters from entering into a transaction with exporters from entering into a transaction with knowledge that a violation of those laws has knowledge that a violation of those laws has occurred or is about to occur. They also contain occurred or is about to occur. They also contain prohibitions against doing business with certain prohibitions against doing business with certain specified persons and certain countries; exporting specified persons and certain countries; exporting to prohibited end-uses or end-users; and to prohibited end-uses or end-users; and contributing to the proliferation of weapons of mass contributing to the proliferation of weapons of mass destruction and delivery systems. To avoid destruction and delivery systems. To avoid violating these prohibitions, an exporter must make violating these prohibitions, an exporter must make sure they are not dealing with a restricted party or sure they are not dealing with a restricted party or possible proliferators. In short, possible proliferators. In short, exporters have a exporters have a duty to exercise “reasonable care”duty to exercise “reasonable care” in investigating in investigating the parties involved in, and the nature of, its export the parties involved in, and the nature of, its export transactions.transactions.

Page 5: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Questions to ask yourselfQuestions to ask yourself

Are you screening?Are you screening? Why are you Why are you

screening?screening? Who is screening?Who is screening? How are you How are you

screening?screening? What are you What are you

screening for?screening for?

Who are you Who are you screening?screening?

When are you When are you screening?screening?

How often are you How often are you screening?screening?

Page 6: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Suggested PracticeSuggested Practice

Page 7: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

As you can see, every As you can see, every visitor in our company visitor in our company has to come through has to come through the front door, go the front door, go through DPS and be through DPS and be badged. We start the badged. We start the process early.process early.

FYI – we did not FYI – we did not conduct DPS on 3 conduct DPS on 3 week old Baby Brody, week old Baby Brody, but we did for his but we did for his mom.mom.

Page 8: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

DPS ProcessDPS ProcessDenied Party

Screening(DPS)

Is there a DPS match?

Is it a direct hit? (DPS & citation

applicable)

Contact TCO, Investigate & get

verification: name, entity, address,

citation(ie. Verification

statement with D/L, passport, VISA)

SUSPEND ACTIVITY

(Do not approve transaction)

Record & File(ie. Visitor form,

DPS, etc.)

NOTIFY PARTY(ie. Cannot complete

transaction)

Record & File(ie. Visitor form,

DPS, etc.)

GOProceed with

Activity

Yes

No Yes

No

Verified – Not a Hit

Cannot Verify

Page 9: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Lists to CheckLists to Check

Lists to check Lists to check include:include: Denied PersonsDenied Persons Entity ListEntity List Unverified ListUnverified List OFAC ListsOFAC Lists Nonproliferation Nonproliferation

SanctionsSanctions Debarred ListDebarred List

Its burdensome for Its burdensome for companies that do companies that do not have all not have all inclusive software inclusive software to check all these to check all these lists which makes it lists which makes it easier for people to easier for people to “forget” to screen.“forget” to screen.

Page 10: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

What are Red Flags?What are Red Flags?

Possible indicators that an unlawful Possible indicators that an unlawful diversion might be planned by the diversion might be planned by the customercustomer

Abnormal or suspicious circumstancesAbnormal or suspicious circumstances There are obvious red flags and not so obvious There are obvious red flags and not so obvious

red flags. Most people that work in compliance red flags. Most people that work in compliance tend to have a gut feel when they think tend to have a gut feel when they think something is fishy. Go with that feeling and do something is fishy. Go with that feeling and do your best due diligence to keep your company your best due diligence to keep your company out of jeopardy.out of jeopardy.

Page 11: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Examples of Red FlagsExamples of Red Flags

The customer or its address is similar to one of the parties The customer or its address is similar to one of the parties found on one of the denied person’s lists. found on one of the denied person’s lists.

The customer or purchasing agent is reluctant to offer The customer or purchasing agent is reluctant to offer information about the end-use of the item. information about the end-use of the item.

The product's capabilities do not fit the buyer's line of The product's capabilities do not fit the buyer's line of business, such as an order for sophisticated computers for business, such as an order for sophisticated computers for a small bakery. a small bakery.

The item ordered is incompatible with the technical level of The item ordered is incompatible with the technical level of the country to which it is being shipped, such as the country to which it is being shipped, such as semiconductor manufacturing equipment being shipped to semiconductor manufacturing equipment being shipped to a country that has no electronics industry.a country that has no electronics industry.

The customer is willing to pay cash for a very expensive The customer is willing to pay cash for a very expensive item when the terms of sale would normally call for item when the terms of sale would normally call for financing.financing.

The customer has little or no business background. The customer has little or no business background.

Page 12: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Examples of Red Flags Examples of Red Flags (cont’d)(cont’d)

The customer is unfamiliar with the product's performance The customer is unfamiliar with the product's performance characteristics but still wants the product. characteristics but still wants the product.

Routine installation, training, or maintenance services are Routine installation, training, or maintenance services are declined by the customer. declined by the customer.

Delivery dates are vague, or deliveries are planned for out Delivery dates are vague, or deliveries are planned for out of the way destinations. of the way destinations.

A freight-forwarding firm is listed as the product's final A freight-forwarding firm is listed as the product's final destination. destination.

The shipping route is abnormal for the product and The shipping route is abnormal for the product and destination. destination.

Packaging is inconsistent with the stated method of Packaging is inconsistent with the stated method of shipment or destination. shipment or destination.

When questioned, the buyer is evasive and especially When questioned, the buyer is evasive and especially unclear about whether the purchased product is for unclear about whether the purchased product is for domestic use, for export, or for re-export. domestic use, for export, or for re-export.

Page 13: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Hits or Matching RecordsHits or Matching Records When DPS Results in “Hits”When DPS Results in “Hits”

Read and check the detailed resultsRead and check the detailed results Investigate and exclude any possibility of a coincidence or a Investigate and exclude any possibility of a coincidence or a

similar sounding name or entity.similar sounding name or entity. Review the citation. There are instances where a name/entity Review the citation. There are instances where a name/entity

and citation may result in a match, but the citation does not and citation may result in a match, but the citation does not prohibit this particular business transaction.prohibit this particular business transaction.

Verify the name/entity, address, and citation using the DPS Verify the name/entity, address, and citation using the DPS Verification Statement form to document due diligence. Verification Statement form to document due diligence.

Verification should include at a minimum the completion of the DPS Verification should include at a minimum the completion of the DPS Verification Statement form in which the name/entity, date, Verification Statement form in which the name/entity, date, signature and statement of the individual attesting they are not signature and statement of the individual attesting they are not excluded from US government export/import activity and rejecting excluded from US government export/import activity and rejecting being a denied party are included along with a copy of a driver’s being a denied party are included along with a copy of a driver’s license, passport, or visa, if applicable. A template is available.license, passport, or visa, if applicable. A template is available.

Record and file the verification statement and all relevant Record and file the verification statement and all relevant communication.communication.

Proceed with the business transaction.Proceed with the business transaction. If verification cannot be obtained or the party is unwilling to If verification cannot be obtained or the party is unwilling to

provide the necessary information, it is suggested to suspend provide the necessary information, it is suggested to suspend activity until there is cooperation, or terminate the activity. activity until there is cooperation, or terminate the activity.

Page 14: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

DPS Verification StatementDPS Verification Statement

I,_________________ , certify that I am not the same person(s) or I,_________________ , certify that I am not the same person(s) or entity listed on the denied party screening performed by Millitech. entity listed on the denied party screening performed by Millitech. Further, I certify that I am presently not facing any penalties or Further, I certify that I am presently not facing any penalties or have affected privileges with the U.S. Government regarding have affected privileges with the U.S. Government regarding export/import regulations. Millitech has provided a printout of the export/import regulations. Millitech has provided a printout of the list of name(s) and/or address(es) which resulted from conducting list of name(s) and/or address(es) which resulted from conducting my name/entity search, and I verify that the names/entity, my name/entity search, and I verify that the names/entity, residences, and affected privileges have no relation to me. residences, and affected privileges have no relation to me.

Prior to entering the facility and/or proceeding with a business Prior to entering the facility and/or proceeding with a business transaction/activity, I have provided Millitech a copy of my driver’s transaction/activity, I have provided Millitech a copy of my driver’s license (or Visa/Passport) which Millitech will keep in their files for license (or Visa/Passport) which Millitech will keep in their files for verification and record keeping purposes only. verification and record keeping purposes only.

Name:__________________________Date:______________Name:__________________________Date:______________

Signature:_______________________Signature:_______________________

Page 15: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Direct Hits (exact match)Direct Hits (exact match)

When DPS Results in a “Direct Hit” (name and When DPS Results in a “Direct Hit” (name and citation applicable)citation applicable)

Read and check the detailed results. Read and check the detailed results. Verify it is a direct hit. Notify TCO.Verify it is a direct hit. Notify TCO.

Suspend the transaction or activity processSuspend the transaction or activity process Inform the customer/visitor the transaction is on “hold” pending Inform the customer/visitor the transaction is on “hold” pending

a further detailed investigation of export/import compliance a further detailed investigation of export/import compliance matters and that there may be a delay or prolonged process matters and that there may be a delay or prolonged process times.times.

Do not approve orders, sign off forms, release shipments or Do not approve orders, sign off forms, release shipments or authorize exports or visits.authorize exports or visits.

Record and file all documentation. Record and file all documentation. Notify the party that this transaction cannot be completed Notify the party that this transaction cannot be completed

due to export/import compliance matters.due to export/import compliance matters. It is recommend that this communication be documented and It is recommend that this communication be documented and

filed with DPS related records for future reference.filed with DPS related records for future reference. STOP ACTIVITYSTOP ACTIVITY

Page 16: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Example – Employee Example – Employee Millitech interviewed a potential technician Millitech interviewed a potential technician

in March 2009. We ran a DPS, no in March 2009. We ran a DPS, no matching records.matching records.

Millitech hired this technician in July 2009. Millitech hired this technician in July 2009. We ran a DPS and at this time we had our We ran a DPS and at this time we had our first direct hit on a person.first direct hit on a person.

The alert was for a HUD (Housing and The alert was for a HUD (Housing and Urban Development) offense.Urban Development) offense.

We asked the employee about this finding We asked the employee about this finding and he admitted that he and his family and he admitted that he and his family had been indicted for a HUD crime and had been indicted for a HUD crime and that they were waiting for the trial.that they were waiting for the trial.

Page 17: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Example – Employee Example – Employee (cont’d)(cont’d)

Our President, HR, Finance Director and Our President, HR, Finance Director and myself called our legal group and talked myself called our legal group and talked about this topic and how to proceed.about this topic and how to proceed.

Our decision was based on his job Our decision was based on his job description:description: His job does not entail anything financialHis job does not entail anything financial He would have no access to moneyHe would have no access to money He was on a 6 month trial (not because of DPS He was on a 6 month trial (not because of DPS

finding) and if anything came up we would finding) and if anything came up we would dismiss him at that time dismiss him at that time

We hired this technician and had no issues We hired this technician and had no issues with himwith him

Page 18: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Example - VisitorExample - Visitor George W. Bush comes to visit and wants to George W. Bush comes to visit and wants to

partner with us on a defense RFP we are working partner with us on a defense RFP we are working on:on: George W. Bush is an alias used by many peopleGeorge W. Bush is an alias used by many people George does come up with an alert and you find that George does come up with an alert and you find that

this person is not allowed to work on government this person is not allowed to work on government contractscontracts

Since we know this is not the same George Bush Since we know this is not the same George Bush being found on the lists that we are working with being found on the lists that we are working with we ask him to verify his identity and have him we ask him to verify his identity and have him sign the DPS verification statement and we can sign the DPS verification statement and we can continue to work with himcontinue to work with him

Page 19: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Example - SupplierExample - Supplier Bharat Electronics Ltd - IndiaBharat Electronics Ltd - India

When you look up this company you get When you look up this company you get a country code alert.a country code alert.

In this example India companies are In this example India companies are on a watch list for atomic energy on a watch list for atomic energy (nukes) products.(nukes) products.

If Millitech was selling them If Millitech was selling them components that would fall into this components that would fall into this category we would stop the activity category we would stop the activity or apply for a license.or apply for a license.

Page 20: Denied Party Screening Best Practices by Cindy Peeters Millitech, Inc. Technology Control Officer/Facility Security Officer

Questions?Questions?

Cindy PeetersCindy Peeters

[email protected]@millitech.com