This post is part of a series based on our recent webinar, When FOCI Stops the Deal: A Guide for FSOs and Executive Teams. Watch the full recording for more context.
For defense contractors operating under a Foreign Ownership, Control, and Influence (FOCI) mitigation agreement, the board is not a typical corporate governance structure.
It is a regulated governance instrument with composition, duties, reporting, and recordkeeping requirements set by 32 CFR Part 117 (National Industrial Security Program Operating Manual (NISPOM) Rule) and overseen by the Defense Counterintelligence and Security Agency (DCSA).
Dig deeper below to learn more.
When DCSA determines a company is under FOCI and that risk cannot be addressed through a simple board resolution, it requires a more structured mitigation instrument. 32 CFR 117.11(d)(2) lays out the available methods. Three of them involve restructuring the board of directors:
For more background on the full range of FOCI mitigation instruments, see our companion blog: When FOCI Stops the Deal: A Guide for FSOs and Executive Teams.
The defining feature of a FOCI-mitigated board is the tension built into its design.
Inside directors represent the foreign shareholder. They sit on the board, participate in business management consistent with the mitigation agreement, and often view the FOCI board as secondary to the parent company structure. That perspective creates friction from the start.
Outside directors must meet specific regulatory requirements under 32 CFR 117.11(f). They must be:
That last point is broader than people sometimes assume. The disqualifying relationship is not just with the foreign shareholder. It includes the entity itself and any affiliated entities.
As Paul Michaels, CEO of Monoc Securities LLC and a longtime industrial security professional, described it:
“You have a group that is a mixture of representatives of the shareholder who want things to happen a certain way, and then another group that was selected by the shareholder but could not have a preexisting relationship with them, who has been tasked to look out for DCSA’s interests.”
The practical effect: outside directors carry the standard fiduciary duties of any board member plus a regulatory duty to insulate the cleared entity from foreign influence. When those duties pull in different directions, the regulatory duty governs. That is the structural source of the tension every FOCI board has to manage.
Under 32 CFR 117.11(g), any contractor operating under an SCA, SSA, VT, or PA must establish a permanent committee of its board of directors called the Government Security Committee. The GSC is where the day-to-day work of FOCI compliance lives.
Composition. Unless DCSA approves otherwise, the GSC consists of all cleared outside directors, proxy holders, or voting trustees, plus any cleared officer-directors. The FSO and Technology Control Officer (TCO) typically serve as advisors.
Meeting frequency. The Center for Development of Security Excellence (CDSE)’s Outside Director / Proxy Holder training materials confirm the standard cadence: the GSC and the broader board are expected to meet quarterly, at minimum. Many GSCs meet more often during periods of organizational change or active compliance activity.
Primary responsibilities under 32 CFR 117.11(g)(2). The GSC ensures the contractor:
In practice, that translates into a defined set of operational responsibilities laid out across the NISPOM Rule and DCSA guidance. The GSC and outside directors are responsible for putting in place, and maintaining oversight of, the supplements required under 32 CFR 117.11(h):
The job description most FSOs read describes their role as “an advisor to the board.” That undersells what the regulation actually says.
Per 32 CFR 117.11(g)(3): “The contractor’s FSO will be the principal advisor to the GSC and attend GSC meetings. The chairman of the GSC must concur with the appointment and replacement of FSOs selected by management. The FSO functions will be carried out under the authority of the GSC.”
Three things matter here:
Key FSO responsibilities in a FOCI-mitigated environment:
The structural tension between inside and outside directors is expected. The job of leadership is to manage it, not eliminate it.
Education is the most effective tool. Michaels recommends bringing in independent outside counsel, separate from your regular corporate legal team, to train the full board on the requirements of the mitigation agreement.
This approach accomplishes two things:
DCSA also provides direct training resources you should be using. CDSE offers a baseline Outside Director / Proxy Holder curriculum (IS175) that walks individuals through the regulatory framework, GSC responsibilities, and compliance expectations. DCSA convenes initial meetings with new outside directors and proxy holders and conducts annual compliance meetings. Outside directors are expected to attend.
Having board training on the record is not just administrative housekeeping. It is the difference between a manageable DCSA finding and a serious compliance issue if something goes wrong later.
The goal is not to eliminate disagreement between inside and outside directors. It is to ensure that everyone understands the boundaries when disagreements occur, and that the outside directors have the standing, the regulatory backing, and the documented training to enforce them.
Companies that have already been through FOCI mitigation and established a functioning board structure are in a stronger position than many realize, particularly as the proposed FOCI expansion rule moves forward.
On May 7, 2026, the Department of Defense (DoD) (also known as the Department of War) published a proposed DFARS rule that would extend FOCI disclosure and mitigation requirements to unclassified DoD contracts and subcontracts valued over $5 million. The comment period closed July 6, 2026, with a final rule anticipated later this year. DoD projects the rule will expand DCSA’s annual FOCI caseload from roughly 2,000 cases to approximately 41,000, covering up to $200 billion in acquisitions not currently subject to FOCI vetting.
Cate Pearson, President of Managed Security Services at ISI, put it like this: “This presents a really good opportunity for you to go to your board, to your inside directors who were reluctant to be FOCI mitigated, and explain to them how their peers, your competitors, are all going to have to go through fresh FOCI reviews. You have already been through it, you have already passed it, and you are going to be a little bit ahead of the game.”
For companies with existing FOCI boards, the priority now is keeping the structure current:
Whether you are building a FOCI board for the first time or running one that has been in place for years, the fundamentals are the same:
For background on the FOCI mitigation process and what instruments are available, see: When FOCI Stops the Deal: A Guide for FSOs and Executive Teams.
The two instruments are used in different ownership scenarios. Under 32 CFR 117.11(d)(2)(ii), a Security Control Agreement (SCA) is used when a foreign interest does not effectively own or control the entity but is entitled to representation on the governing board. An SCA requires at least one cleared U.S. citizen to serve as an outside director, and there are no access limitations under an SCA. Under 32 CFR 117.11(d)(2)(iii), a Special Security Agreement (SSA) is used when a foreign interest does effectively own or control the entity. The SSA preserves the foreign owner’s right to board representation while denying the foreign owner majority representation and unauthorized access to classified information. Access to proscribed information under an SSA generally requires a National Interest Determination (NID).
The FOCI mitigation structure is specifically designed to insulate cleared operations from foreign influence. Under an SSA, the foreign owner is denied majority board representation and “unauthorized access to classified information.” Decisions involving classified programs, personnel security, and FOCI compliance run through the cleared outside directors and the Government Security Committee. Inside directors representing the foreign shareholder do not participate in those decisions and do not have access to classified information unless they are independently cleared and an NID supports that access.
DCSA takes outside director conduct seriously. A violation can result in the director being removed and replaced, additional scrutiny of the company’s FOCI mitigation program, and in serious cases, suspension or revocation of the facility clearance under 32 CFR 117.11(a)(7). That is why training, documented compliance, and clear governance procedures are not optional.
Under 32 CFR 117.11(g)(3), the FSO is the principal advisor to the GSC, FSO functions are carried out under the GSC’s authority, and the GSC chairman must concur with FSO appointment and replacement. Operationally, the FSO still reports to the SMO for day-to-day matters. Most experienced FSOs handle this by establishing written protocols at the outset: which decisions go through management, which go through the GSC, and which require GSC chairman concurrence. Putting it in writing prevents ambiguity when an issue is moving fast.
CDSE’s Outside Director / Proxy Holder guidance directs quarterly board and GSC meetings at minimum. More frequent meetings are appropriate during periods of significant organizational change, mitigation agreement updates, or active compliance activity. DCSA also conducts annual compliance meetings that outside directors are expected to attend.
On May 7, 2026, DoD published a proposed DFARS rule that would extend FOCI disclosure and mitigation requirements to unclassified DoD contracts and subcontracts valued over $5 million. The comment period closed July 6, 2026, and a final rule is anticipated later in 2026. If you already operate under a FOCI mitigation agreement for classified work, you are already inside the framework the rule is designed to expand. The practical implication is competitive: many contractors who have never been through FOCI review are about to be, and they will be working against your existing track record of compliance.