A Facility Security Officer (FSO) rarely has one job on any given day. Cleared facility oversight, training, incident response, and visitor management often land on the same desk, and sometimes at the same hour.
Foreign national and export-controlled visitors add a layer that has nothing to do with facility clearance and everything to do with what a visitor might see, hear, or access while they're on-site.
Dig deeper below to learn more.
ITAR (22 CFR Parts 120 through 130) doesn't publish a single section titled “visitor requirements.” Instead, the obligation comes from a simpler principle: giving a foreign person access to controlled technical data or defense articles, even inside the United States, can count as an export. That's called a deemed export, and it applies whether the visitor is a prospective customer, a subcontractor's engineer, or a university researcher touring a lab.
That means a visit isn't a facilities question. It's an export-control event, and the FSO is usually the one deciding, in real time, whether it's authorized.
The day usually starts with an email, or a calendar invite the FSO didn't create. The program manager wants to bring in an engineering partner on Thursday. A sales team wants to walk a foreign customer through the shop floor. Neither request mentions export control, because that's not the FSO’s job to think about.
The FSO's first move should be the same every time:
Before anyone sends a building pass, the visitor gets screened against restricted party and denied persons lists, and their nationality gets checked against any country-specific ITAR restrictions.
A few things the FSO is trained to never assume:
If the visit requires a license or falls outside an existing exemption, the visit doesn't happen on the original timeline. That's an uncomfortable conversation with a program manager who already booked the visitor's flight, but it's the FSO's job to discuss it anyway.
Once a visit is cleared to proceed, the TCP dictates the rest of the day:
A TCP is supposed to be a living document, not something drafted once and filed away. If the facility layout, program scope, or workforce has changed since the plan was last reviewed, this is where those gaps surface.
Having a visitor simply sign in isn't sufficient. The FSO (or a trained designee) needs to be able to say, with confidence, that the visitor was never left alone in an area where they could encounter technical data, hardware, or a controlled conversation.
That's a harder standard than it sounds. A visitor left alone, even for as little as two minutes, near an unlocked terminal or an open whiteboard is still considered an access event whether anyone intended it or not.
ISI Insight: The FSOs who handle this best aren't the ones with the most experience. They're the ones who've stopped treating visitor logs, foreign contact reporting, and training records as three separate problems to track.
Also, the visit ending isn't the end of the FSO's day. Every visit needs a record: who visited, what they were screened against, what areas they accessed, who escorted them, and what business justification supported the visit in the first place.
This is where a lot of ITAR visitor programs can quietly fail. The screening happened, the escort happened, but the documentation lives in someone's inbox or a spreadsheet nobody else can find during an audit. This is part of why ISI built visit tracking and foreign contact reporting directly into Security Control, our own security management platform. The workflows run without scripting or IT setup, which matters most for FSOs without a dedicated export-control specialist on staff or an engineering team to build something custom. When the record lives in the same system as training and facility clearance data, it's there when someone asks for it.
ITAR visitor scrutiny has tightened. Foreign national access incidents, inadequate escort procedures, and missing documentation show up regularly in enforcement outcomes, and DDTC has made clear that informal or verbal-only screening is no longer treated as sufficient.
At the same time, most FSOs are managing this alongside personnel and facility clearance oversight, training compliance, and Defense Counterintelligence and Security Agency (DCSA) security reviews and self-inspections, often without a dedicated export-control specialist on staff. Visitor screening lives in one process, facility clearance records live in another, and training completions live in a third. Growth multiplies the workload without multiplying the FSO's hours in the day.
By the time the FSO locks up for the day, the visit itself was the easy part. The screening judgment, the escort discipline, and the paper trail behind it are what keep a company's ITAR program defensible.
No. Giving a foreign person access to controlled technical data or defense articles inside the United States can itself be an export, known as a deemed export. A visit, a lab tour, or a shared screen can trigger the same obligations as shipping a physical item.
It varies by organization, but the FSO is often the one making real-time access determinations, even though ITAR is enforced by the Department of State's DDTC rather than the Department of War or DCSA. Many FSOs manage this alongside their National Industrial Security Program Operating Manual and facility clearance responsibilities.
Assuming a signed visitor log is enough. Auditors and DDTC reviewers look for documented screening decisions, escort accountability, and a business justification tied to each visit, not just proof that someone showed up.
No. Security Control tracks visit records, foreign contact reporting, training, and facility clearance data in one system, but the legal determination behind a deemed export or an export license requirement still requires the FSO's review. The platform is built to make that record defensible, not to make the call for you.
Security Control includes out-of-box workflows for visit renewals and foreign contact tracking, alongside training reminders and incident reporting, with no scripting or IT setup required. Across its customer base, the platform processes roughly 40,000 visit requests a year, end to end, from notification to renewal.