FAI documentation becomes ITAR-controlled technical data when it contains, reproduces, or is derived from technical data directly related to a defense article controlled on the U.S. Munitions List. It is not ITAR-controlled merely because it is an AS9102 first article inspection record. The controlling factors are the jurisdiction of the part or program, the source data used, and whether the FAI package discloses design, manufacturing, inspection, testing, or acceptance information that meets the ITAR definition of technical data.
This is a classification and export-control determination, not a document-format rule. A blank AS9102 form is not normally controlled. A completed FAI package for a controlled missile, military aircraft component, or other USML item may be controlled if it includes dimensions, tolerances, material specifications, process requirements, special inspection methods, test parameters, ballooned drawings, nonconformance dispositions, or other information needed to produce, inspect, test, maintain, or modify the defense article.
Common cases where FAI records may become controlled
- Ballooned drawings: If the drawing is ITAR-controlled, a ballooned version is usually treated as controlled because it reproduces and organizes the same technical data.
- Completed AS9102 forms: Characteristic numbers, drawing zones, nominal values, tolerances, measured results, material callouts, process specifications, and acceptance criteria may disclose controlled production or inspection data.
- Attached objective evidence: CMM reports, special process certifications, lab results, test data, photographs, and supplier certificates can be controlled when they reveal controlled requirements or performance data.
- Derived records: Even if a system does not store the original drawing, an extracted inspection plan or digital characteristic list can still be controlled if it was derived from controlled technical data.
What usually does not decide the issue by itself
ITAR control is not determined solely by whether the record is in MES, QMS, ERP, PLM, a supplier portal, Net-Inspect, email, or a file share. The storage location matters for access control and auditability, but the classification follows the content and jurisdiction.
Contract markings are important operational signals, but they are not the whole analysis. A document can be controlled even if it is poorly marked, and a customer may also apply conservative markings that require handling controls under contract even where the legal jurisdiction still needs confirmation. In practice, sites should not rely on operators or inspectors to infer export classification from the FAI form alone.
Brownfield system implications
In mature aerospace and defense plants, FAI data often crosses PLM, MES, QMS, ERP, document control, supplier portals, and long-lived file repositories. That creates failure modes: uncontrolled exports through supplier access, replicated attachments, report downloads, email notifications, backups, analytics extracts, and integrations that strip markings or access restrictions.
Full system replacement is usually unrealistic in these environments. Qualification burden, validation cost, downtime risk, integration complexity, traceability obligations, and long asset lifecycles often make replacement a poor first move. More commonly, organizations need a controlled data-handling model across existing systems: classification metadata, role-based access, export-screened users, controlled supplier workflows, audit trails, retention rules, and change control for integrations that move FAI data.
Practical boundary
Treat FAI documentation as potentially ITAR-controlled when it is tied to a USML-controlled part, defense program, controlled drawing package, or controlled manufacturing or inspection requirement. Do not assume that removing the drawing attachment makes the FAI safe to share; extracted characteristics and measured results may still reveal controlled technical data.
Final classification should follow the organization’s export-control process, with input from the program owner, customer flow-downs, engineering, contracts, and qualified export compliance personnel. This is not an area where a generic MES, QMS, or document-control setting can guarantee a compliant outcome.