FOCI Compliance and the Supplier Ownership Problem

Cover image (Option B, the org chart with question marks): "A blog header image for Trust Your Supplier showing the title FOCI Compliance and the Supplier Ownership Problem on a blue background, with a green organizational chart on the right side showing multiple ownership tiers, several of which are marked with question marks to indicate unknown or unverified ownership.

For decades, FOCI compliance has been a defense industry requirement. If you wanted to work with the US Department of Defense, you had to prove your company, and your suppliers, weren't secretly controlled by a foreign government. That rule is specific, well established, and strictly enforced. 

Now the same question is showing up in industries that have never had to answer it before. 

What FOCI Actually Asks 

Knowing the name of your supplier isn't the same as knowing who's behind it. 

FOCI compliance asks a harder question: who owns this company? Who controls it? And is any ownership tied to a foreign government, a state-owned enterprise, or someone politically connected? 

Here's why that's harder than it sounds. A supplier might be incorporated locally, but its parent company sits in another country. That parent might be majority-owned by a sovereign wealth fund. One board member might hold a senior political position somewhere else entirely. None of that shows up when you check the company name or where it's registered. 

Regulators don't want a list of suppliers you happen to know are government-owned. They want proof you have a real process for finding out. 

Why This Is Spreading  

This isn't a hypothetical. FOCI-style requirements are already expanding into new sectors and new countries, and each one is coming at the problem from a different angle. 

In Australia, regulators are working directly with electrical companies on new rules that would require them to map their supply chains and flag foreign ownership risk. In the US, FERC and CISA are building similar supply chain requirements for critical infrastructure, on top of what's already required in defense. The CHIPS Act is putting the same pressure on manufacturers to understand who owns their suppliers. 

In the EU, DORA requires financial institutions to understand who owns and controls their technology vendors. And anti-bribery laws around the world already require screening for politically exposed people in third-party relationships, regardless of industry. 

Different regulators, different angles, same underlying demand: show us you know who's behind your suppliers, and show us you're still checking.

Why Checking Once Isn't Enough 

Most procurement and compliance teams handle this the same way they handle most things outside their core workflow: they go with what they happen to know. 

Someone on the team knows a supplier is government-owned because they've been around long enough to know. The team scans the news for ownership changes. The annual risk review is treated as the safety net. 

The problem is that ownership doesn't stay still. A supplier that was privately owned when you signed them might be owned by a foreign state-owned company today. A board member who was a private citizen during your last review might hold a government position now. 

A team relying on memory and news alerts can't catch that kind of change at scale, and it can't produce what regulators are starting to ask for: documented ownership entities, risk scores, match details, and a record showing the review actually happened. 

We cover topics like this every week. Practical supplier management insights for procurement and supply chain teams. Get it in your inbox →

What Automated Ownership Screening Covers

A two-column diagram. The left column shows six ownership entity types screened in sequence from top to bottom: Global Ultimate Owner, Domestic Ultimate Owner, Immediate Owner, Beneficial Owners above 5%, Current Principals, and Executive Contacts including CEO, CFO, and CRO. All are screened against global sanctions, watchlists, and PEP databases. The right column shows four monitoring behaviors: daily monitoring runs automatically on all established vendors; rescreening triggers automatically when a supplier updates ownership or business details; a potential match generates an automatic approval request for team review; and monitoring stops automatically when a supplier is offboarded.
Click image to enlarge

TYS automatically checks supplier ownership against global sanctions and watchlist data. 

This goes beyond the company name on the contract. It covers beneficial owners holding 5% or more, immediate owners, domestic and global ultimate owners, and current company principals, with politically exposed persons screened as part of the same check.

When something matches, the system doesn't file it away for someone to find later. It opens an approval request immediately, with a clear view of who matched, how confident the match is, and where the information came from. 

This runs daily across all established vendors. If ownership changes or a new watchlist entry appears, a new approval request is generated automatically. If a supplier updates their information, they get rescreened automatically too. And it's not just ownership, all company principals, including executives like the CEO, CFO, and CRO, are monitored continuously as part of the same process. 

The result: you get an answer to the ownership question that doesn't go stale, and you get a paper trail showing the checking actually happened, without anyone having to build that trail by hand. 

What To Do Now 

FOCI compliance outside of defense is still taking shape. That's actually an advantage if you move now: you get to build this capability deliberately, on your own timeline, instead of scrambling once it becomes mandatory. 

Three questions worth asking yourself this week: 

If someone asked you right now who owns your top suppliers, not the legal name, but the actual people and entities behind them, could you answer? If the honest answer is "we'd have to go look it up," that's not a position you want to be in once regulators start asking. 

Is anyone checking this more than once? A single check at onboarding tells you nothing about what's true a year later. Ownership has to be monitored the same way you'd monitor any other ongoing risk. 

If an auditor asked for proof, could you produce it? Not a verbal "yes, we checked," but actual documentation, match details, decisions, and a history of when the checks happened. 

If you're in energy, utilities, financial services, or critical infrastructure, this is worth asking now, before someone outside your organization asks it for you.

Interested in how TYS approaches FOCI screening? Reach out.

 


Blog Compliance Management Risk Management
Previous reading
FOCI Compliance and the Supplier Ownership Problem
Next reading
China’s New Supply Chain Decrees: What Procurement Teams Need to Know Right Now