BAE Systems Hit With $36m US Penalty After 104 Defence Export Control Violations
BAE Systems has agreed to pay a $36 million civil penalty to the US Department of State after an extensive compliance review identified 104 alleged violations of American defence trade export...
BAE Systems has agreed to pay a $36 million civil penalty to the US Department of State after an extensive compliance review identified 104 alleged violations of American defence trade export controls, including unauthorised transfers of controlled technical data to several countries, including China.
The settlement, reached under the Arms Export Control Act, AECA, and International Traffic in Arms Regulations, ITAR, is a significant reminder that export compliance failures can arise not only from physical shipments of military equipment, but from the movement of controlled technical information across borders. The violations included unauthorised exports of technical data, breaches of conditions attached to export authorisations and unauthorised exports of defence articles.
The case is particularly instructive because BAE voluntarily disclosed all but one of the alleged violations and cooperated with the State Department’s investigation. A substantial portion of the conduct also predates 2023, while the company has since implemented improvements to its ITAR compliance programme.
Under the 36-month consent agreement, $18 million of the $36 million penalty is suspended, provided the money is applied to State Department approved remedial compliance measures. The agreement also requires enhanced compliance oversight, including an external Special Compliance Officer and independent auditing of BAE’s ITAR compliance programme.
The Compliance Story
The BAE case exposes a familiar but increasingly expensive corporate compliance problem: technology can cross a border without a crate ever leaving a warehouse.
Engineering drawings, technical specifications, software, military GPS information and other controlled data can constitute regulated defence articles or technical data under ITAR. An unauthorised electronic transfer, access by an unauthorised foreign person or movement between corporate facilities can therefore create an export control violation.
That makes compliance software and systems architecture particularly important. The issue is not simply whether a company possesses an export control policy. It must be capable of identifying controlled information, restricting access, determining who is authorised to receive it and maintaining an auditable record of transfers and approvals.
The BAE settlement therefore carries a broader message for multinational defence, aerospace and technology companies. A compliance system that cannot see where controlled data is going cannot reliably control where controlled data goes.
The China Dimension
The involvement of China gives the case an additional national security dimension. Among the alleged violations were unauthorised exports of technical data to China, while other breaches involved countries including Canada, the UK, Germany, Italy, France, Indonesia and Switzerland.
This demonstrates how a multinational’s internal network can become an export control perimeter. A company may have legitimate operations in several allied jurisdictions, yet the same technical information may remain subject to US licensing requirements when transferred between subsidiaries, employees, contractors or foreign persons.
The compliance challenge is consequently both geographical and technological.
Compliance Takeaway
Export control compliance must extend into the company’s technology infrastructure.
Defence and technology companies need to know what controlled data they hold, where it resides, who can access it, where recipients are located, what authorisation covers the transfer and whether those controls remain effective across subsidiaries, contractors and cloud environments.
BAE’s $36 million settlement also demonstrates the value regulators place on voluntary disclosure, cooperation and remediation, while showing that those factors do not necessarily eliminate substantial financial and supervisory consequences.
The larger lesson is stark: in defence trade, a compliance failure involving data can become a national security enforcement matter.



No Comment! Be the first one.