KNOWLEDGE IS POWER: It May Be Time to Redefine KYC
KNOWLEDGE IS POWER: It May Be Time to Redefine KYC
For more than 30 years, one concept has been drilled into my head as an export compliance professional: Know Your Customer (KYC).
Know who you are selling to. Know where the product is going. Know the ultimate consignee and end user. Know what they intend to do with it. Know whether the parties are restricted. Know whether the destination is sanctioned or embargoed. Know your product, its jurisdiction and classification, and whether an export license is required.
This is not merely some compliance catchphrase that we invented along the way. The Bureau of Industry and Security (BIS) maintains formal “Know Your Customer” guidance within Supplement No. 3 to Part 732 of the Export Administration Regulations (EAR). It specifically instructs companies to consider “red flags” involving the end user, end use, destination and other abnormal circumstances surrounding a transaction.
Those of us who have lived in export compliance for a while know the alphabet soup well: BIS, EAR, OFAC, ITAR, RPL, DPL, SDN, CCL, ECCN, NLR, ENC, CJ, DSP-5, EUS, DCS, AES, EEI, ACE and enough others to make a normal person’s head spin.
And yes, I know. Technically many of these are Three-Letter Abbreviations (TLAs), and more specifically initialisms, rather than acronyms. An acronym is generally pronounced as a word, like RAM or LASER. Apparently after three decades in global trade, these are the sorts of things that now occupy valuable space in my brain.
Anyway, I digress.
The point is that KYC has always been about knowledge. Don’t blindly accept what someone tells you. Perform the due diligence. Screen. Research. Document. Investigate the red flags. When something doesn’t make sense, stop and figure out why.
For years we called it “trust, but verify.” I increasingly believe we have that backwards. In today’s trade environment, it should probably be VERIFY, and then trust.
More importantly, I don’t think knowing your customer is nearly enough anymore.
Enforcement Has Changed
Before getting to my growing collection of KY-whatevers, we need to acknowledge why this matters. Trade enforcement is changing quickly, and the numbers should get the attention of every importer and exporter.
The Department of Justice (DOJ) and Department of Homeland Security (DHS) launched a Trade Fraud Task Force (TFTF) in 2025. In July 2026, DOJ announced that the task force had surpassed $1 billion in civil and criminal recoveries, penalties, forfeitures and publicly charged losses in less than one year. DOJ also reported that CBP had assessed more than $2.1 billion in commercial trade penalties so far during Fiscal Year 2026. The government is explicitly describing its strategy as combining criminal prosecution with civil enforcement, including use of the False Claims Act (FCA).
We are already seeing what that can look like. In May, Perfectus Aluminum and related companies agreed to pay $549.5 million to settle False Claims Act allegations concerning antidumping and countervailing duties on Chinese aluminum extrusions. In July, Redi-Bag USA and its CEO agreed to pay $7.3 million to resolve allegations involving misrepresented country of origin and antidumping duties. In another case involving plastic resin imports, a former executive agreed to plead guilty in connection with false country-of-origin declarations allegedly used to avoid Section 301 duties.
This is one of the developments that concerns me most. We are no longer talking only about an entry correction, a bill from Customs or even a civil penalty. Trade fraud is increasingly being viewed through multiple enforcement lenses, and companies need to understand the potential consequences.
The government also has tremendous amounts of data. DOJ itself describes its broader fraud-enforcement mission as relying on advanced, data-driven investigative techniques and coordination among government agencies. CBP’s own audit program describes the use of data analysis and risk-assessment procedures in determining the scope of audits.
So perhaps it is time we expanded KYC.
KYS / KYSC: Know Your Supplier / Know Your Supply Chain
For years, importers routinely asked suppliers for an HTS classification, country of origin or Free Trade Agreement (FTA) certification and put it in the file. Supplier says it is Italian? Great, Italy. Supplier provides a USMCA certification? Fantastic, claim USMCA. Invoice says $10,000? Wonderful, enter $10,000.
Those days should be behind us.
Forced-labor enforcement has demonstrated how little many companies actually know about their extended supply chains. Knowing your Tier 1 supplier may be nowhere near enough when regulators expect evidence regarding upstream manufacturers, raw materials and production processes. The same principle applies well beyond forced labor.
Do you understand the actual manufacturing process? Can you substantiate origin? Have you validated the FTA qualification instead of merely accepting the certificate? Do you understand assists, royalties, commissions, proceeds and other valuation considerations? Do you know whether ADD/CVD applies? Do you understand enough about the manufacturing process and sourcing structure to evaluate legitimate tariff, origin or procurement engineering opportunities?
A supplier’s assurance that “we’ve always done it this way” may be comforting. It is not evidence.
KYD: Know Your Data
This one may be my favorite because if knowledge is power, data is a superpower.
I continue to encounter sophisticated multinational companies that don’t have adequate access to their own trade data. Some don’t have ACE accounts. Others have ACE access for only some legal entities. Trade information sits fragmented among ERP systems, brokers, forwarders, spreadsheets, procurement systems, engineering databases, finance systems, emails and someone’s mysterious shared drive that apparently hasn’t been cleaned since 2009.
Meanwhile, the government is analyzing the data you submitted to them.
Companies should be able to access and connect HTS classifications, ECCNs, country of origin, valuation data, Bills of Material (BOMs), technical specifications, manufacturing records, purchase orders, invoices, entry data, AES/EEI filings, transportation records, ACE data, sanctions and denied-party screening information, supplier information, audit results, corrections and historical compliance decisions.
The question I would ask leadership is simple: If the government questioned 500 transactions tomorrow, how long would it take us to assemble the evidence?
If the answer is weeks, or worse, “I’m not sure,” you have identified a problem.
Your competitors may also understand their data better than you understand yours. That creates more than a compliance disadvantage. Better data can mean better sourcing decisions, better tariff forecasting, quicker identification of errors, faster responses to regulators and ultimately lower landed costs. Poor data can therefore become a competitive disadvantage.
Artificial Intelligence (AI) belongs in this conversation as well. AI can help identify anomalies, organize records, analyze enormous datasets and improve efficiency. But technology does not eliminate the need for knowledgeable human oversight. The answer is not to fear the technology or blindly trust it. Use it, understand what it is doing, validate the results and maintain the human expertise necessary to recognize when something doesn’t look right.
KYP: Know Your Partners
I remember when many companies essentially handed a stack of half-baked documents to their Customs Broker or International Freight Forwarder (IFF) and said, “Take care of it.”
Unfortunately, plenty still do.
Your broker, forwarder, Third-Party Logistics provider (3PL), attorney, consultant, managed-services provider and technology company may perform work on your behalf, but that does not mean you have outsourced your responsibility.
Have you properly vetted them? Do you have meaningful Standard Operating Procedures (SOPs)? Are Powers of Attorney (POAs) current and appropriate? Are they providing useful Key Performance Indicators (KPIs)? Do they have internal quality controls? Are their employees adequately trained? Are their systems keeping pace with regulatory change? Most importantly, are you auditing what they are doing in your name?
The same applies to technology and data security. If a partner uses AI or automation, understand how it is being used and where human oversight enters the process. If you are providing a third party with sensitive business information, understand their cybersecurity controls, Non-Disclosure Agreements (NDAs), business-continuity plans and backup procedures.
You chose these companies to become an extension of your organization. Know them accordingly.
KYT: Know Your Transactions
Having beautiful master data is wonderful, but eventually the rubber has to hit the road. The actual import or export transaction is where your compliance program becomes real.
Did the correct HTS actually appear on the entry? Was the correct country of origin reported? Were the appropriate Chapter 99 provisions applied? Did the tariff stacking work correctly? Did your export arrive where everyone said it was going? Were the necessary permits, quotas, licenses and certificates available?
This is where longtime Vigil readers know what I am going to say: audit, audit, audit.
But don’t audit only the convenient transactions flowing neatly through your ERP. Look for the weird ones too: sales samples, hand carries, repair shipments, engineering prototypes, replacement parts, laptops shipped to foreign employees and whatever somebody tossed into a suitcase because “it’s not really a shipment.”
Those are often the transactions that come back to bite you.
Export professionals also understand that not every export comes in a box. Controlled technical information can create export-control concerns when released to foreign persons, including in certain circumstances people physically located in the United States. Emails, facility tours, technical discussions and electronic access may therefore require controls just as physical shipments do.
Knowing your transactions means getting your arms around all of them, including the ones that don’t fit neatly into the standard process.
KYE: Know Your Enforcers
This one makes some companies uncomfortable, but I believe you should know your regulators.
I have encountered organizations that treat CBP, BIS and other government agencies a little like Voldemort: don’t say the name, don’t make eye contact and perhaps they won’t notice us.
I’m not convinced that’s the best strategy.
Earlier in my career, a company I worked for experienced significant border delays involving another government agency. Emails weren’t solving it. More documents weren’t solving it. In fact, things seemed to be getting worse. I contacted the port, eventually drove to the border and sat down with the government officials and CBP officers. I spent about an hour teaching them about our products, suppliers and processes.
The delays stopped.
Years later I experienced something similar involving air shipments at a major airport. A conversation with the port director, a flight to the port and roughly 30 minutes explaining our business resolved an issue that had been causing repeated delays.
Sometimes their problem is also a knowledge problem.
This does not mean inviting enforcement into your conference room unnecessarily. It means understanding who regulates you, what they are concerned about, what they are enforcing and how they communicate. Know your CBP Center of Excellence and Expertise (CEE). Understand programs such as Customs Trade Partnership Against Terrorism (CTPAT). CBP itself identifies benefits of CTPAT participation that include assignment of a Supply Chain Security Specialist, eligibility for certain programs and priority consideration at industry-focused Centers.
Read enforcement cases from CBP, BIS, OFAC and DOJ. Pay attention to what foreign customs authorities are doing as well. Canada’s CBSA, for example, currently identifies tariff classification, valuation and origin among its trade-compliance verification priorities and has highlighted areas including surtaxes and FTA origin verification.
Attend BIS Updates when possible. Attend CBP’s Trade and Cargo Security Summit. Read the Federal Register. Subscribe to CSMS. Follow government announcements and Executive Orders, but remember our earlier rule: verify, and then trust. What matters operationally is ultimately the controlling legal authority and implementing guidance.
KYF: Know Your Future
Compliance professionals spend an enormous amount of time looking backward. What did we import? What did the broker file? What happened? What went wrong?
Those are necessary questions, but they aren’t enough.
Where is your company going? What acquisitions are being considered? What countries will you enter? Where will Procurement source next year? What products is Engineering developing? What does the CEO want the company to become? What are shareholders demanding?
If your company’s future is Mexico while your entire compliance infrastructure is designed around China, you have work to do. Trade Compliance needs a seat at those tables before decisions are finalized.
You don’t want to discover after an acquisition that you inherited years of compliance skeletons. You don’t want to discover after signing a sourcing contract that the expected duty savings don’t exist. You certainly don’t want leadership asking why nobody anticipated a regulatory development the industry had been discussing for six months.
This also means watching what is happening outside the compliance department. Follow politics, economics, geopolitical relationships, wars, sanctions, natural disasters, labor disruptions and technology. Follow your own company’s strategy. You cannot predict everything, but you can stop being surprised by everything.
Technology is a particularly important part of knowing your future. Many of us “old folks” in trade remember classifying products with an enormous paper HTS sitting on our desks. Then came Global Trade Management (GTM) systems, automation and increasingly sophisticated analytics. Now AI is arriving and producing another round of anxiety.
Ignoring it will not make it go away.
BIS’s own compliance guidance emphasizes management commitment, risk assessment, written procedures, recordkeeping, training, audits and maintaining a compliance program that remains current with the organization’s activities. That is a useful way to think about technology too. Don’t surrender the compliance program to a machine, but don’t refuse to use tools that can make knowledgeable professionals more effective.
Perhaps KYC Needs a New Definition
After working through all of this, I don’t think we should abandon KYC. I think we should make it bigger.
KYC started as Know Your Customer, but today’s trade professional needs a much broader field of vision:
- KYS / KYSC: Know Your Supplier / Know Your Supply Chain
- KYD: Know Your Data
- KYP: Know Your Partners
- KYT: Know Your Transactions
- KYE: Know Your Enforcers
- KYF: Know Your Future
That is an impressive number of abbreviations, even for a trade nerd. But all of them ultimately belong underneath one larger KYC:
KNOW YOUR COMPLIANCE.
Know what you do, why you do it, who does it for you and what your data says. Know where your risks are. Know what the government knows. Perhaps most importantly, know what you don’t know, and build a network that helps you fill those gaps.
None of us can possibly know everything anymore. That is one reason organizations such as the International Compliance Professionals Association (ICPA), NCBFAA, AAEI and other trade communities have become so valuable. Your professional network isn’t merely good for your career. Increasingly, I believe it is part of your compliance infrastructure.
On September 13, Vigilant will be sponsoring the ICPA Global Trade Pathways Conference in Grapevine, Texas, where I’ll also be presenting. If you’re there, come find us. Attend the sessions. Ask uncomfortable questions. Talk with the speakers, exhibitors, attorneys, consultants, technology providers and, most importantly, the other trade professionals dealing with the same insanity you are.
You don’t have to know everything. You do need to know enough to recognize what you don’t know, and where to find the answer.
Knowledge is power. Data is a superpower. Verify, then trust. And above all, KNOW YOUR COMPLIANCE.
Stay vigilant.
Jamie Adams, LCB, CCS
References and Further Reading
These sources provide regulatory guidance and supporting background for the concepts discussed above:
- U.S. Bureau of Industry and Security, Export Administration Regulations, Part 732, Supplement No. 3: BIS “Know Your Customer” Guidance and Red Flags. This is the regulatory foundation for the traditional export-control KYC concept discussed in the article.
BIS EAR Part 732 and KYC Guidance
- U.S. Department of Justice, “Trade Fraud Task Force Surpasses $1 Billion in Recoveries and Charged Losses in Less Than One Year,” July 14, 2026. Includes the $1 billion Trade Fraud Task Force figure, CBP’s FY2026 commercial trade penalty figure and examples of recent trade-fraud enforcement.
DOJ Trade Fraud Task Force Enforcement Results
- U.S. Department of Justice, Redi-Bag USA and CEO False Claims Act Settlement, July 15, 2026. Provides a recent example involving alleged misrepresentation of country of origin and evasion of antidumping duties.
DOJ Redi-Bag Customs Duties Settlement
- U.S. Department of Justice, MGI International Criminal Trade Fraud Investigation, December 18, 2025. Addresses alleged falsification of country-of-origin declarations to avoid Section 301 duties and the related criminal resolution.
DOJ MGI International Trade Fraud Case
- U.S. Bureau of Industry and Security, Export Compliance Programs. BIS outlines its elements of an effective Export Compliance Program, including management commitment, risk assessment, procedures, recordkeeping, training and program maintenance.
BIS Export Compliance Programs
- U.S. Bureau of Industry and Security, Voluntary Self-Disclosure. BIS guidance regarding VSDs under the EAR and the role of corrective action when violations are identified.
BIS Voluntary Self-Disclosure Guidance
- U.S. Customs and Border Protection, Trade Regulatory Audit. Describes CBP’s use of data analysis, risk assessment and internal-control evaluation in its audit activities.
CBP Trade Regulatory Audit
- U.S. Customs and Border Protection, Customs Trade Partnership Against Terrorism (CTPAT). Provides information regarding CTPAT participation, Supply Chain Security Specialists and program benefits.
CBP CTPAT Program
- Canada Border Services Agency, Trade Compliance Verification, updated July 2026. Provides current Canadian verification priorities involving classification, valuation, origin and other trade-compliance areas.
CBSA Trade Compliance Verification
- U.S. Department of State, Directorate of Defense Trade Controls, DSP-5 guidance. Provides the official description and guidance concerning permanent export licensing for unclassified defense articles and related technical data under ITAR.
DDTC DSP-5 Licensing Guidance