US Federal Law United States

EO 14117 Vendor Diligence: Screening for the DSP

Vendor and counterparty diligence under the DOJ Data Security Program: covered-person screening, ownership-chain analysis, workforce-location attestations, and contract clauses that work.

Regulation

28 CFR Part 202 due-diligence obligations (from October 6, 2025); CISA Security Requirements; DOJ NSD guidance and FAQs

Max Penalty

Knowingly directing or participating in prohibited transactions carries IEEPA penalties; 'knowledge' includes reason to know, so diligence failures are themselves the liability theory

Enforcing Authority

US Department of Justice, National Security Division

Official Source

www.justice.gov

Executive Summary

  • The DSP makes counterparty diligence a legal requirement for restricted transactions: written, risk-based procedures to verify data flows and vendor identity, certified annually and audited independently.
  • Covered-person status hides in three places screening must reach: ownership chains (50-percent rules through layered entities), workforce location (employees and contractors primarily resident in countries of concern), and DOJ designations.
  • 'Knowledge' under the rule includes reason to know: unexamined red flags convert a vendor's covered status into your violation.
  • Contract architecture carries the program: workforce-location and access representations, onward-transfer restrictions for any foreign data brokerage, CISA-requirement flow-downs, audit rights, and termination triggers.
  • The screening stack resembles sanctions compliance more than privacy vendor review: entity resolution, beneficial-ownership data, and periodic re-screening on a risk cadence.

DSP diligence is sanctions compliance wearing a privacy costume, and companies that grasp that early save themselves a rebuild. The operative concepts, 50-percent ownership cascades, designation lists, reason-to-know liability, evasion indicators, come from OFAC practice, not vendor security review, and the tooling follows: entity resolution and beneficial-ownership data, continuous list monitoring, escalation files. What the DSP adds is the workforce-location dimension (your vendor’s org chart is now a regulated fact) and the contract layer (onward-transfer restrictions the rule itself drafts for you). The uncomfortable core is the knowledge standard: after October 2025, ‘we never asked who owns them’ is not ignorance, it is the violation.

MandatedWritten program, data-flow verification, vendor identity, annual certification + audit, 10-yr records
Screen forOwnership (50% cascades), workforce location, DOJ designations
StandardKnowledge includes reason to know
Contract coreStatus reps, access warranties, onward-transfer bans, audit rights, termination
CadenceRisk-tiered annual + event-driven re-screening
AuthorityDOJ NSD Data Security Program

Operationalizing the screens

Reuse the sanctions stack. Add the DOJ Covered Persons List to existing screening pipelines; entity-resolution tooling handles the 50-percent cascades the bulk-data rule defines.

Make workforce location contractual. Questionnaire answers decay; representations with change-notification duties do not. Tech-company patterns show where access hides.

Repaper by exposure, not alphabet. Vendors with standing covered-data access first; renewals carry the rest.

Build the escalation file. Red flags, inquiries, conclusions, dated; under a reason-to-know standard, the documented inquiry is the compliance. General vendor-management discipline supplies the operating rhythm.

Your data-flow verification starts client-side: inventory what your site sends to which parties with a free scan.

Frequently Asked Questions

What diligence does the rule actually mandate, and for whom?

For US persons engaging in restricted transactions (vendor, employment, non-passive investment agreements involving covered-person access to bulk covered data), 28 CFR 202 requires, since October 6, 2025, a written data compliance program including: risk-based procedures for verifying data flows (types, volumes, transaction parties, end use); for vendors specifically, procedures verifying identity; written policies annually certified by an officer; annual independent audit; and 10-year records. For prohibited-transaction avoidance, no formal program is prescribed, but the knowledge standard does the work: you may not knowingly engage in data brokerage with a covered person, and knowledge includes circumstances where you reasonably should have known, so every company transacting in covered data needs at least screening sufficient to catch what a reasonable inquiry would find. DOJ's guidance frames expectations proportionally: a data broker selling geolocation feeds owes more inquiry than a company whose vendor touches covered data incidentally.

How do we screen for covered-person status through ownership chains?

Apply logic learned from OFAC's 50 Percent Rule, with the DSP's own definitions. A foreign entity is a covered person if 50 percent or more owned, individually or in the aggregate, by a country of concern or by covered persons, ownership cascades through layers, so a Delaware vendor's Singapore parent majority-held by PRC state entities makes the chain covered even though no single link looks alarming. Screening stack: beneficial-ownership data providers (corporate registries, D&B/Sayari-class tools), sanctions and designation lists (DOJ's Covered Persons List plus OFAC lists, since designated persons overlap), and direct questionnaires with ownership representations where data is thin. Escalation triggers for enhanced review: opaque holding structures, recent re-domiciling out of countries of concern, nominee shareholders, and unusually favorable pricing for data access (DOJ flags below-market terms as an evasion indicator). Document the search, the sources, and the conclusion per counterparty; the file is the defense.

What workforce-location questions must vendor diligence now ask?

Because a covered person includes foreign employees and contractors of country-of-concern entities and foreign individuals primarily resident in countries of concern, the vendor's staffing map is a compliance fact. Ask: where are the personnel (employees and subcontractors) who will have logical or physical access to our covered data primarily resident? Does the vendor operate development, support, or operations centers in countries of concern, and can those roles reach covered systems? What access controls segregate them (deny-by-default, masking, credential scoping per the CISA requirements)? How is access change managed when staffing shifts? Extract the answers into contract representations, not just questionnaire responses: an ongoing warranty that no covered-data access will be granted to personnel primarily resident in countries of concern (or, if the transaction is run as restricted, that CISA controls govern such access), with notification duties when staffing changes would alter the answer. The question set parallels what defense contractors ask under export-control regimes; procurement teams can borrow those templates nearly verbatim.

What clauses should DSP-aware contracts contain?

Six clusters. Status representations: counterparty warrants it is not a covered person, with ownership-change notification duties. Workforce and access: representations on personnel location and covered-data access paths, CISA-requirement compliance where applicable, and audit or attestation rights. Onward-transfer restrictions: for any data brokerage with foreign persons, the rule-mandated contractual prohibition on resale or transfer to countries of concern or covered persons, plus your duty to report known violations to DOJ within the required window. Use limitation: covered data used solely for the engagement, no aggregation into products reaching restricted counterparties. Remedies: termination rights on covered-status change or representation breach, cooperation duties in your DOJ reporting, records retention matching your 10-year obligation. Certification support: information delivery sufficient for your annual officer certification and independent audit. Legacy contracts need a remediation sweep, the rule did not grandfather existing arrangements, and renewal cycles are the natural repapering vehicle, prioritized by data exposure.

How should re-screening and monitoring work over time?

Covered-person status is dynamic: acquisitions change ownership math, staffing moves change workforce exposure, and DOJ adds designations. Risk-tier the cadence: counterparties with standing access to bulk covered data get re-screening on ownership and designations at least annually plus event triggers (M&A announcements, restructuring, designation-list updates, media reporting linking them to countries of concern); lower-exposure vendors get designation-list monitoring and renewal-time refresh. Wire triggers into existing systems, sanctions-screening platforms already run continuous list monitoring, and adding the DOJ Covered Persons List to that pipeline is cheap; contract-management systems can flag ownership-notification receipts for review. When a counterparty turns covered mid-relationship: access suspension per your contract, transaction reclassification (can this continue as a restricted transaction under CISA controls, or is it now prohibited brokerage?), and documentation of the timeline, because what you knew when, and what you did within what period, is precisely what an NSD inquiry reconstructs.

Regulatory Crosswalk

OFAC 50 Percent Rule analogiesKYC/sanctions screeningThird-party risk management programs

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.