A comprehensive visitor management program will include, as a baseline, a well-defined visitor management process. Visitor management processes may look very different from one organization to the next (depending on the export-compliance risks, number of sites, amount of support staff, etc.). However, below are a few general guidelines that should be incorporated, in one form or another, in most visitor management processes and programs. Keep in mind that this guidance may be well-suited for export-compliance purposes but does not necessarily incorporate other visitor management concerns such as physical security or access to confidential or proprietary business information.
A visitor access process should include the following steps:
Visitors who require access to U.S. export-controlled products/technologies should submit to their host employee some form of document or other written confirmation including their date(s) of visit, employer, reason for visit and type of products/technologies they seek to access.
Visitors who require access to U.S. export-controlled products/technologies should submit to their host employee (or to on-site security, export control, etc.) either proof of citizenship (passport or birth certificate) or proof of permanent-resident status (e.g., a green card) to establish if they are export-compliant. Be aware that different forms of state ID (e.g., a state driver’s license or state government ID) may demonstrate proof of U.S. nationality in some U.S. states but not in others.
The documentation described above should be reviewed by an employee trained to understand which nationalities may or may not pose export-compliance risks given the products and technologies at issue. While it may be necessary or preferred at some companies to direct all visitor requests and accompanying documentation to a centralized export-compliance team, it is often more manageable to train on-site employees to handle such reviews and to only escalate specific visitor management issues or concerns to a centralized export-compliance team.
Site visitors should be screened (via a local or centralized function) to ensure they are not on prohibited or restricted-party lists. Screenings that produce a “hit” should be escalated to determine if it is truly a restricted party or rather a false positive.
Assuming that visitors' on-site access is approved, a badge should be assigned so they, as well as other employees on-site, are aware of areas they can or cannot access. Badging may be color-coded to not only denote that an individual is a visitor (as opposed to an employee or contractor) but also to establish that a particular visitor is or is not export-compliant. Here is an example of a three-tiered badging system:
Most companies, even those without significant deemed-export concerns, will have a visitor management process in place for physical security purposes. For export-compliance professionals looking to develop or improve on an existing visitor management process, it would befit them to coordinate with internal security stakeholders to determine where there are overlapping interests and room for collaboration.
It may not be feasible or even necessary to screen every visitor, to every site, every day. Depending on the size of a company and/or the export-compliance risks at hand, it may be reasonable to find ways to prioritize the sites and types of visitors that need to be screened, documented and approved based on a number of risk factors, including:
Remember, just because an unlicensed foreign-national visitor walks into a room containing a piece of export-controlled equipment or technology, an export-control violation has not necessarily (and not likely) occurred. While export-compliance professionals tend to be overly cautious, it is also incumbent on them to balance the risks with the time and effort involved in implementing a visitor management process that could potentially be overly cumbersome to the business.
Many of a company’s visitors may be the employees of vendors that a company uses every day, such as delivery professionals, maintenance workers, etc. These vendors may be asked (or required in their contracts) to confirm their employees' nationalities and/or screen them against restricted party lists to be allowed on-site at your company.
While an export-compliance professional may want to keep tabs on the nationality of every site visitor, be aware that certain countries—especially European countries subject to the General Data Protection Regulation (GDPR)—have privacy restrictions that dictate the reason such information can be collected, how long it may be retained, the manner of retention, etc. Export-compliance professionals should confirm with the local privacy-compliance professionals within their organization before attempting to broadly implement a visitor management process or policy that may require adjustments from one country to another.
A common scenario faced by many export-compliance officers goes as follows: An employee calls and says, “We have a big group of visitors coming from ABC Company tomorrow, we are taking them on a site tour … what do we need to do?”
Granted getting a day’s notice is better than no notice, situations like the preceding can be lessened (although probably never completely avoided) if employees are trained on the visitor access process and instructed to put in visitor requests “ahead of time”—48 hours, one week or even a month—as defined in the applicable visitor management process.
While there may be instances of screenings and reviews being conducted last minute and on the spot with a visitor waiting in the lobby, such scenarios should be the exception, not the rule. Employees who are hosting visitors should be held accountable for the lead times specified in the visitor management process, and export-compliance officers should be ready to give instruction to deny or limit access to a visitor who has not been properly screened. If an export-compliance professional isn’t empowered to implement such restrictions, an escalation plan should be in place.
If a visitor coming on-site hasn’t been properly screened ahead of time (or has been screened and poses an export-compliance risk due to nationality), the visitor does not necessarily need to be prohibited from entering a site. Below are a few creative, compliant means to still accommodate a site visit:
Like what you read? Subscribe today to the International Trade Blog to get the latest news and tips for exporters and importers delivered to your inbox.