Problems & solutions · Supply Chain

ITAR and Export Control Software Problems: The 7 That Create Violations, and How to Avoid Them

Itar Export Control Software workflow illustration showing common problems and fixes.
The short answer

The most expensive failure is a build that promises enforcement everywhere and delivers it in one place. Access is blocked in the engineering vault, and the same drawing sits in a file share, an email attachment, a supplier quote folder and a shop floor viewer with no control at all. The Empowered Official now has a system that reports compliance and a reality that is not, which is a materially worse position than an honest gap, because a documented control that does not work is what turns an oversight into a finding.

Why does the enforce everywhere first release collapse?

Export control projects attract total scope for an understandable reason: partial control feels like no control. So release one is scoped to enforce across the engineering vault, the file shares, email, source repositories, the enterprise resource planning (ERP) system and the shop floor viewer at once. Each of those has a different permission model, a different owner in information technology, and a different appetite for being changed. Eighteen months later, two are integrated and the programme has lost its budget.

What makes this specific to a defence manufacturer is that the enforcement points are owned by people whose objectives are not compliance. The engineering systems team measures itself on engineer productivity. Restricting access by nationality is friction they did not ask for. Every integration is therefore a negotiation as much as a build, and negotiations do not parallelise.

The sequence that works starts with the two things everything else depends on: a classification workspace tied to your part master, and a person register fed from human resources carrying nationality, status and the authorisations each individual is named on. Those two deliver value on their own, because for the first time you can produce a list of what is controlled and who may see it. Enforcement then follows one system at a time, highest exposure first, with each integration scoped and negotiated on its own terms.

What goes wrong when you load classifications and the part master?

Classification history lives in email. The same part has been classified twice by two people two years apart, sometimes differently, usually without the reasoning recorded. The instinct is to harvest those decisions into the new system so the backlog starts smaller. That is precisely the mistake, because a determination without its reasoning, its citation and its approver is not a determination, it is an assertion. Loading it makes the system authoritative about something it cannot defend.

The specific failure surfaces in an audit or during acquisition due diligence. Someone asks on what basis a part was classified as United States Munitions List Category VIII and the record shows a category with a migration timestamp and no approver. That reads worse than an unclassified backlog, because it implies a control that was never exercised.

The part master brings its own problems. Revisions that should inherit a classification are recorded as separate parts. Assemblies reference obsolete children. Supplier parts sit in a different numbering scheme entirely. Loading that untouched means bill of materials rollups, which are the feature people ask for constantly, return answers nobody trusts.

Handle both by loading structure and not conclusions. Bring in the part master, the revision relationships and the bill of materials, and bring historic classifications in as unapproved proposals requiring review rather than as determinations. Where a model proposes a category from part descriptions, drawing notes and specification references, it produces a review item with the relevant regulation text alongside, never a record. The Empowered Official or a trained analyst approves, or nothing is classified.

Why do the PLM and HR integrations break after launch?

Product lifecycle management is the harder of the two and it breaks structurally rather than intermittently. Windchill, Teamcenter and 3DEXPERIENCE each have their own permission model, and none was designed for nationality based access. Driving group membership from classification and nationality works until an engineer creates a new context, a workspace or a folder that inherits permissions from somewhere your rules do not reach. Nothing errors. A controlled document simply sits somewhere the enforcement logic does not see.

The fix is to audit rather than assume. Reconcile, on a schedule, the set of locations holding controlled technical data against the set of locations your enforcement covers, and raise any difference as an exception with a named owner. That report is more valuable than any dashboard, because it measures the gap rather than the coverage.

Human resources breaks on timing and on data quality. A contractor's status changes and the feed carries it days later, which is days of access that should have ended. Nationality and immigration status are often held in free text or in a field maintained for a different purpose, and dual nationality is frequently not modelled at all. Both need to be specified explicitly during discovery, because a person register built on a field that means something slightly different from what you assumed is the quietest possible failure in this entire category.

What happens when deemed exports and drawdown are not properly covered?

Two gaps produce actual violations rather than inefficiency. The first is the deemed export. Under the International Traffic in Arms Regulations, releasing controlled technical data to a foreign person is treated as an export to that person's country even inside your own facility in the United States. There is no shipment and no border. Preventing it requires three facts joined at the moment of access: what the data is classified as, who the person is in terms of citizenship and status, and whether an authorisation covers that release. Trade compliance owns the first, human resources the second, information technology the third, and almost nowhere are they joined.

The second is licence and agreement drawdown. A DSP-5 authorises specific articles or technical data, to specific parties, up to a value, until an expiry. A Technical Assistance Agreement names parties and sublicensees and scopes what may be discussed. Tracking consumption in a spreadsheet updated after the fact from shipping records works until you hold thirty active authorisations and a sales engineer promises a customer a design review next week. Exceeding the value or releasing to a party outside the agreement is a violation even though you hold the authorisation.

Fix both structurally. Authorisations become records with articles, parties, value, provisos and expiry, and every controlled transaction consumes against them at the moment it occurs, with provisos as checklists that must be satisfied rather than paragraphs somebody skimmed. Where genuine enforcement is impossible, say so explicitly and implement detection with alerting inside minutes. A partner who tells you which cases are detection rather than prevention is more useful than one who promises prevention everywhere.

Should you build custom or configure what you already own?

Buy if your exports are occasional and mostly EAR99, you employ no foreign persons in engineering, and your real need is restricted party screening. Descartes Visual Compliance is genuinely strong at screening and will do that for a fraction of a build. Buy SAP Global Trade Services if you are a large SAP shop whose primary volume is customs and export declarations rather than engineering data access, because reproducing customs content is not a sensible use of a development budget. OCR Services EASE handles licence management competently and may be enough on its own if drawdown is your only real gap.

None of them sits inside Windchill, Teamcenter, your file shares or your source repositories deciding whether a specific person may open a specific file, because that is not what they were designed to be. If your exposure is engineering data access rather than shipment paperwork, that is the gap you are buying a build to close, and it is the only good reason to build here.

Build when two or more of these are true: you hold controlled technical data and employ foreign persons anywhere in the organisation; you cannot produce today a report of who accessed a given controlled drawing in the last year; your classification decisions live in email; you track drawdown in a spreadsheet after the fact; or you have filed a voluntary disclosure and committed to remediation.

How do hidden costs get into the quote?

Compliant hosting is a real line item rather than a rounding error, and it is regularly missing from first numbers. If your contracts bring Cybersecurity Maturity Model Certification obligations and NIST SP 800-171 controls for controlled unclassified information, the hosting environment, access model and logging must be designed for that from the first sprint. Retrofitting an environment boundary is close to rebuilding the system.

Second, the number of enforcement points, which is the multiplier people underestimate most. Engineering vault, file shares, email, source control, the enterprise system and the shop floor viewer are six integrations, not one, and each carries its own negotiation with a system owner.

Third, false positive management in screening. A rescreening engine that produces hundreds of hits a day gets ignored, and an ignored control is worse than none. The engineering that matters is the hit disposition queue and the tuning, not the matching. Ask specifically what is included per enforcement point and what the hosting assumption is, in writing, before contract.

What separates a build that works from one that fails here?

Ask in the first meeting how they will keep controlled technical data away from their own team. If there is no immediate answer involving synthetic development data, a production boundary restricted to United States persons and brokered, logged support access, end the conversation. A development team that can see production technical data is itself a source of deemed exports, and it is a common way for this to go wrong because everyone is focused on the engineers and nobody thinks about the contractors building the tool.

Ask them to model the objects. Classification determination, authorisation, party, person with nationality and status, controlled transaction and access event should be distinct, and the audit log should be append only by design. A proposal built around a permissions matrix and a document library is a file sharing product.

The builds that work are honest about the boundary between prevention and detection, they put classification and the person register first because everything else depends on them, and they treat every enforcement point as its own negotiated piece of work. The builds that fail promise complete coverage, integrate the two easiest systems, and produce a compliance dashboard that is green while the drawings sit unprotected in a folder nobody mapped.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. 48% of private companies cite integration with legacy systems or technical debt as a top obstacle to realizing the full value of their digital and AI investments (behind data quality/availability at 72% and gaps in AI fluency or technology talent/leadership at 53%). Source: Deloitte (2026) →
  2. Digital Champions expect to achieve about 16% in cost savings and around 15% in revenue gains from digital operations over five years; the study surveyed 1,155 manufacturing executives across 26 countries. Source: PwC / Strategy& (2018) →
  3. Qualtrics research (Q3 2023 survey of ~28,400 consumers across 26 countries) estimated bad customer experiences put roughly $3.7 trillion in global revenue at risk annually, a 19% jump from the prior year's $3.1 trillion; 64% of customers say they will switch companies over poor service regardless of how much they like the product. Source: Qualtrics XM Institute (via Forbes) (2024) →
  4. Only about 30% of digital transformations succeed at meeting their objectives, but getting six critical success factors in place (leadership commitment, talent, agile culture, progress monitoring, clear strategy, and a modernized platform) raises the odds of success from 30% to 80%. Source: Boston Consulting Group (BCG) (2020) →
Oliver H. · Senior Account Director · UK · London

Oliver runs UK client accounts day to day, chairing the calls where scope, budget and timeline meet reality. He is useful reading for anyone about to commission custom software and wondering what a healthy agency relationship should feel like from the client side.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

What should be in the first release of an export control build?
The classification workspace tied to your part master and the person register fed from human resources with nationality, status and named authorisations. Those two are the foundation everything else depends on, and they deliver value alone because you can finally produce a list of what is controlled and who may see it. Enforcement then follows one system at a time, highest exposure first, each scoped and negotiated separately.
Should we load historic classification decisions from email into the new system?
Load them as unapproved proposals requiring review, never as determinations. A classification without recorded reasoning, a regulatory citation and an approver is an assertion, and making the system authoritative about it is worse than showing an honest backlog. During an audit or acquisition due diligence, a category with a migration timestamp and no approver reads as a control that was never exercised.
Can a model classify parts against the USML or the CCL to clear our backlog?
It can propose a category with the relevant regulation text alongside, which turns a blank page into a review and genuinely speeds up tens of thousands of parts. It must not record the determination. Build the system so only the Empowered Official or a trained analyst can approve, with reasoning and citation stored. A model making unreviewed determinations creates exactly the undocumented judgement an audit is designed to find.
Why does enforcement in Windchill or Teamcenter stop working over time?
Because engineers create new contexts, workspaces and folders that inherit permissions from somewhere your rules do not reach, and nothing errors when that happens. The controlled document simply sits outside the enforcement logic. Reconcile on a schedule the locations holding controlled technical data against the locations your enforcement covers, and raise every difference as an exception with a named owner.
What do we need to specify about HR data during discovery?
Exactly which field carries citizenship and immigration status, what it means, how dual nationality is represented, and how quickly a status change reaches the register. Many organisations hold this in free text or in a field maintained for a different purpose, and dual nationality is often not modelled at all. A person register built on a field that means something slightly different from what you assumed is the quietest failure in this category.
Is it realistic to prevent every deemed export with software?
No, and any vendor promising that is overselling. Prevention requires joining classification, person nationality and status, and authorisation at the moment of access, and some systems cannot enforce natively. For those, the honest answer is detection with alerting inside minutes rather than at the next audit. Prefer a partner who tells you which cases are detection over one who promises prevention everywhere.
How do we stop a rescreening engine from being ignored?
Invest in hit disposition and tuning rather than in matching. A system producing hundreds of hits a day gets ignored, and an ignored control is worse than none. The value an auditor cares about is a defensible record showing every hit reviewed by a named person with a recorded reason, so the queue design and the false positive work are the actual engineering, not the list comparison.
What hosting questions should we settle before signing?
Whether the production environment sits in a United States region with access restricted to United States persons, whether your contracts bring Cybersecurity Maturity Model Certification obligations and NIST SP 800-171 controls, and how support access is brokered and logged. Compliant hosting is a real line item, not a configuration setting, and retrofitting an environment boundary later is close to rebuilding the system.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
What does it cost to keep custom software running after launch?
Budget 15-20% of the original build cost per year, which on a $100,000 system means $15,000 to $20,000 for security patches, dependency updates, bug fixes, and small improvements as real usage reveals what the spec missed. Cloud hosting for a typical business application adds $50 to $300 a month on top. Skipping maintenance does not save the money; in Digital Heroes rescue work, unmaintained systems typically need a far more expensive rebuild within about three years.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
What does it cost to maintain custom supply chain software each year?
Budget 15 to 20 percent of the original build cost per year, so roughly $9,000 to $12,000 annually on a $60,000 system, covering hosting management, dependency updates, bug fixes, and small enhancements. Across its maintenance contracts, Digital Heroes sees supply chain systems need more upkeep than typical web apps because carrier APIs, EDI specs, and ERP versions keep changing underneath them. Hosting itself is usually minor, often $100 to $500 per month for a mid-size operation.
Will custom software scale as we add warehouses, SKUs, and order volume?
Yes, if multi-location support and your target volumes are stated requirements at design time, because a schema built for one warehouse is expensive to retrofit for ten. A well-built system on PostgreSQL comfortably handles millions of SKUs and tens of thousands of orders per day on modest cloud hardware, so scaling cost shows up in hosting bills rather than rewrites. Give your agency the 3-year growth picture upfront even if phase one covers a single site.
What questions should I ask a development agency on the first call?
Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.
How long does it take to build custom supply chain software?
Plan on 10 to 14 weeks for a first production release covering one or two core workflows, and 6 to 9 months for a full platform spanning procurement, inventory, and fulfillment. Digital Heroes ships most supply chain MVPs in about 12 weeks with a 4 to 6 person team. Integrations are the schedule risk: each ERP, EDI, or carrier connection typically adds 2 to 4 weeks of build and testing.
How big a development team does a supply chain software project need?
A typical build runs with 4 to 6 people: a project lead or analyst, two or three developers, a QA engineer, and a part-time designer. Digital Heroes staffs most supply chain MVPs this way for 10 to 14 weeks, then drops to 1 or 2 people for maintenance after launch. Bigger is not better here; past 7 or 8 people on a single-product build, coordination overhead usually cancels the added speed.
Who can build a custom supply chain software system?

Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other supply chain software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?