Skip to content

A Day in the Life of an FSO: ITAR Visitor Compliance in Action

Importance of Cybersecurity in Government Contracting
STREAMLINE FSO COMPLIANCE 

See how Security Control automates critical compliance tasks so you can stay DCSA inspection ready.

Listen: A Day in the Life of an FSO: ITAR Visitor Compliance in Action
7:52

Executive Brief

A Facility Security Officer (FSO) rarely has one job on any given day. Cleared facility oversight, training, incident response, and visitor management often land on the same desk, and sometimes at the same hour.

Foreign national and export-controlled visitors add a layer that has nothing to do with facility clearance and everything to do with what a visitor might see, hear, or access while they're on-site.

  • International Traffic in Arms Regulations (ITAR) visitor obligations are not about badges and sign-in sheets alone
  • The real question is whether a visitor could access controlled technical data, and on what authority they were allowed to
  • A single unscreened or unescorted visit can trigger a “deemed export,” even if nothing physically left the building
  • Documentation gaps, not policy gaps, are what auditors and the Directorate of Defense Trade Controls (DDTC) find most often

Dig deeper below to learn more.


What Counts as an ITAR Visitor

ITAR (22 CFR Parts 120 through 130) doesn't publish a single section titled “visitor requirements.” Instead, the obligation comes from a simpler principle: giving a foreign person access to controlled technical data or defense articles, even inside the United States, can count as an export. That's called a deemed export, and it applies whether the visitor is a prospective customer, a subcontractor's engineer, or a university researcher touring a lab.

That means a visit isn't a facilities question. It's an export-control event, and the FSO is usually the one deciding, in real time, whether it's authorized.

7:30 AM: The Visit Request Lands

The day usually starts with an email, or a calendar invite the FSO didn't create. The program manager wants to bring in an engineering partner on Thursday. A sales team wants to walk a foreign customer through the shop floor. Neither request mentions export control, because that's not the FSO’s job to think about.

The FSO's first move should be the same every time:

  • Confirm whether the visitor is a foreign person under ITAR's definition
  • Identify what parts of the facility, and what technical data, the visit would touch
  • Check whether an existing Technology Control Plan (TCP) already covers the scenario, or whether a new determination is needed

9:00 AM: The Screening Question Nobody Skips

Before anyone sends a building pass, the visitor gets screened against restricted party and denied persons lists, and their nationality gets checked against any country-specific ITAR restrictions.

A few things the FSO is trained to never assume:

  • A clean visitor badge from the front desk is not an access decision
  • Lawful permanent resident status can exempt an employee, but it doesn't automatically extend to a visitor
  • Common exemptions, like the public domain exemption under 22 CFR § 125.4, require a documented legal review, not a guess

If the visit requires a license or falls outside an existing exemption, the visit doesn't happen on the original timeline. That's an uncomfortable conversation with a program manager who already booked the visitor's flight, but it's the FSO's job to discuss it anyway.

11:00 AM: Setting Up the Boundaries

Once a visit is cleared to proceed, the TCP dictates the rest of the day:

  • Which areas the visitor can physically enter
  • What technical data, drawings, or hardware must be secured or removed before they arrive
  • Who is assigned to the visitor as an escort, and what that escort is responsible for watching

A TCP is supposed to be a living document, not something drafted once and filed away. If the facility layout, program scope, or workforce has changed since the plan was last reviewed, this is where those gaps surface.

1:30 PM: Escort Duty in Practice

Having a visitor simply sign in isn't sufficient. The FSO (or a trained designee) needs to be able to say, with confidence, that the visitor was never left alone in an area where they could encounter technical data, hardware, or a controlled conversation.

That's a harder standard than it sounds. A visitor left alone, even for as little as two minutes, near an unlocked terminal or an open whiteboard is still considered an access event whether anyone intended it or not.

ISI Insight: The FSOs who handle this best aren't the ones with the most experience. They're the ones who've stopped treating visitor logs, foreign contact reporting, and training records as three separate problems to track.

3:30 PM: Closing the Loop on Documentation

Also, the visit ending isn't the end of the FSO's day. Every visit needs a record: who visited, what they were screened against, what areas they accessed, who escorted them, and what business justification supported the visit in the first place.

This is where a lot of ITAR visitor programs can quietly fail. The screening happened, the escort happened, but the documentation lives in someone's inbox or a spreadsheet nobody else can find during an audit. This is part of why ISI built visit tracking and foreign contact reporting directly into Security Control, our own security management platform. The workflows run without scripting or IT setup, which matters most for FSOs without a dedicated export-control specialist on staff or an engineering team to build something custom. When the record lives in the same system as training and facility clearance data, it's there when someone asks for it.

Why This Workload Keeps Growing

ITAR visitor scrutiny has tightened. Foreign national access incidents, inadequate escort procedures, and missing documentation show up regularly in enforcement outcomes, and DDTC has made clear that informal or verbal-only screening is no longer treated as sufficient.

At the same time, most FSOs are managing this alongside personnel and facility clearance oversight, training compliance, and Defense Counterintelligence and Security Agency (DCSA) security reviews and self-inspections, often without a dedicated export-control specialist on staff. Visitor screening lives in one process, facility clearance records live in another, and training completions live in a third. Growth multiplies the workload without multiplying the FSO's hours in the day.

By the time the FSO locks up for the day, the visit itself was the easy part. The screening judgment, the escort discipline, and the paper trail behind it are what keep a company's ITAR program defensible.


FAQs

Does ITAR only apply to physical exports of hardware?

No. Giving a foreign person access to controlled technical data or defense articles inside the United States can itself be an export, known as a deemed export. A visit, a lab tour, or a shared screen can trigger the same obligations as shipping a physical item.

Who is responsible for ITAR visitor compliance at a company?

It varies by organization, but the FSO is often the one making real-time access determinations, even though ITAR is enforced by the Department of State's DDTC rather than the Department of War or DCSA. Many FSOs manage this alongside their National Industrial Security Program Operating Manual and facility clearance responsibilities.

What's the most common mistake companies make with ITAR visitors?

Assuming a signed visitor log is enough. Auditors and DDTC reviewers look for documented screening decisions, escort accountability, and a business justification tied to each visit, not just proof that someone showed up.

Does Security Control replace the FSO's judgment on ITAR visitor decisions?

No. Security Control tracks visit records, foreign contact reporting, training, and facility clearance data in one system, but the legal determination behind a deemed export or an export license requirement still requires the FSO's review. The platform is built to make that record defensible, not to make the call for you.

What does Security Control track for visitor management?

Security Control includes out-of-box workflows for visit renewals and foreign contact tracking, alongside training reminders and incident reporting, with no scripting or IT setup required. Across its customer base, the platform processes roughly 40,000 visit requests a year, end to end, from notification to renewal.


Helpful ISI Links

Related Posts