Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Empowered Official: The ITAR-Required Export-Control Compliance Role

22 CFR 120.67 defines the Empowered Official ITAR requires every DDTC-registered institution to designate: who can hold it, what independent sign-off authority it requires, and how it differs from a Research Security Officer or EAR compliance lead.

An Empowered Official is not a generic job title for “whoever handles export control” at a research institution — it is a specific, legally defined role required by the International Traffic in Arms Regulations (ITAR) for any organization registered with the Directorate of Defense Trade Controls (DDTC). The role is defined in the regulatory text itself, at 22 CFR 120.67, and it carries personal knowledge, authority, and independence requirements that go beyond what most institutions expect from a compliance job description. This guide covers what the regulation actually requires, who can and cannot fill the role, how it differs from related titles like Research Security Officer, and what a research institution needs in place to have a properly functioning Empowered Official rather than just someone with the title.

What 22 CFR 120.67 actually requires

The current regulatory citation is 22 CFR 120.67. Older secondary sources, university policies, and training materials often still cite 22 CFR 120.25 — that was the section’s number before DDTC’s 2022 restructuring of ITAR Part 120 (an interim final rule published March 23, 2022, effective September 6, 2022) consolidated and renumbered the purposes-and-definitions section. Both citations point to the same substantive requirement; if you see 120.25 in an older policy document, it means the same role.

The regulation defines an Empowered Official as a U.S. person who meets four conditions, all of which must be true at once:

  1. Employment and authority. Directly employed by the applicant organization (or a subsidiary), in a position with actual authority for policy or management — not a contractor or outside consultant retained to advise on compliance.
  2. Written delegation. Legally empowered in writing by the organization to sign license applications and other requests for approval submitted to DDTC on the organization’s behalf.
  3. Regulatory knowledge. Understands the export control statutes and regulations that apply — specifically the Arms Export Control Act (AECA) and ITAR — and understands the criminal, civil, and administrative penalties for violating them.
  4. Independent authority to verify and refuse. Has the independent authority to inquire into any aspect of a proposed export, temporary import, or brokering activity, to verify the legality of the transaction and the accuracy of the information being submitted, and — critically — to refuse to sign a license application or other request for approval without prejudice or other adverse recourse from the organization.

That last clause is easy to skim past, but it is the provision that makes the role meaningful rather than symbolic. An Empowered Official who can be overruled, penalized, or quietly reassigned for declining to sign a request does not meet the regulatory definition, regardless of what their business card says. DDTC’s expectation, reflected consistently in enforcement history and public guidance, is that the Empowered Official’s sign-off is a substantive compliance check, not a rubber stamp built into someone’s existing job.

One narrow exception exists for brokering activity: where the broker itself is a foreign person, the Empowered Official for that specific brokering registration may also be a foreign person who otherwise satisfies the same four criteria. This exception is specific to brokers and does not extend to ordinary DDTC manufacturer/exporter registrants, which is the category almost all research institutions fall into if they register at all.

Who can — and can’t — realistically hold the role at a university

Because the regulation requires “authority for policy or management,” the role is generally held by someone senior enough to actually bind the institution and refuse a request without institutional retaliation: a vice president or associate vice president for research, a general counsel or associate general counsel, a chief research compliance officer, or the director of an export control or research security office who reports at a sufficiently senior level. What the regulation rules out, in practice:

  • Outside counsel or an export-control consultant retained on a contract basis — they are not “directly employed” by the institution as 120.67 requires, even if they are more knowledgeable about ITAR than anyone on staff.
  • A junior compliance analyst or administrator with day-to-day export-control duties but no real authority to refuse a request from a principal investigator, dean, or vice president without professional consequence. This is a common gap: institutions sometimes give someone the Empowered Official title as part of a compliance-coordinator job without giving them the organizational standing 120.67 actually contemplates.
  • Someone who has not been briefed on AECA/ITAR penalties specifically. The knowledge requirement in 120.67(a)(3) is not generic “compliance awareness” — DDTC’s expectation is documented, specific familiarity with the statute and regulation and their penalty structure, which is why most institutions pair the appointment with export-control-specific training, not general research-compliance onboarding.

Institutions that register multiple business units or campuses with DDTC, or that want continuity when the primary Empowered Official is unavailable, typically also designate one or more Alternate Empowered Officials (Alternate Responsible Officers) who independently meet the same four criteria. An alternate is not a lesser or informal role — DDTC expects an alternate to be fully qualified to sign on the registrant’s behalf, not simply someone who can be consulted.

Empowered Official vs. Research Security Officer vs. “export control officer”

These titles get used loosely and interchangeably in practice, which causes real confusion during a DDTC registration renewal or an internal audit. They are not the same thing:

  • Empowered Official is an ITAR-specific, regulatory term of art defined at 22 CFR 120.67. It exists specifically for organizations registered with DDTC and is tied to the authority to sign export license applications and related requests.
  • Research Security Officer (RSO) is a role created by National Security Presidential Memorandum 33 (NSPM-33), a distinct federal research-security policy that requires covered institutions receiving federal research funding to designate a person responsible for the institution’s overall research security program — foreign-influence disclosure, cyber and information security, travel security, and insider-threat awareness. An RSO’s remit is broader than export control and is not defined in ITAR or the Export Administration Regulations (EAR) at all.
  • “Export control officer” or “export compliance officer” is an informal, institution-created title, not a term defined in either ITAR or the EAR. Many institutions use it for the person who runs day-to-day deemed-export screening, technology control plans, and license tracking — but holding that title alone does not make someone the Empowered Official unless they also independently satisfy 120.67’s four conditions and have been formally, legally empowered in writing to do so.

In practice, a single senior administrator often holds more than one of these titles at once at a smaller institution, and a large research university may split them across a compliance office. What matters for regulatory purposes is not the title on the org chart but whether the specific 120.67 criteria are actually met by whoever is signing DDTC submissions.

Does the EAR require an Empowered Official too?

No — this is a common misconception worth correcting directly. “Empowered Official” is an ITAR-specific requirement administered by DDTC at the State Department. The Export Administration Regulations (EAR), administered by Commerce’s Bureau of Industry and Security (BIS) and governing dual-use items under the 15 CFR Part 734 framework, do not define an equivalent named role or impose the same written-delegation requirement. Institutions that handle both ITAR-controlled defense articles and EAR-controlled dual-use items commonly have the same person, or the same office, function as both the ITAR Empowered Official and the institution’s de facto EAR compliance lead — but that second function exists as institutional practice, not as a distinct EAR-mandated title. Don’t assume a university’s EAR compliance program is deficient just because no one holds an “EAR Empowered Official” title; that title has no regulatory basis to begin with. See 5 Actions Required for EAR Compliance for what the EAR does actually require of an institution’s program.

What the Empowered Official actually does at a research institution

Day to day, the role typically covers:

  • Signing and reviewing DDTC submissions — license applications, technical assistance agreements, manufacturing license agreements, and the institution’s own DDTC registration and renewal, commonly filed on Form DS-2032.
  • Classification sign-off for items or technical data proposed against the US Munitions List (USML), including reviewing a principal investigator’s or export control office’s proposed classification before it becomes the institution’s position of record.
  • Reviewing and approving deemed export screening determinations for foreign national researchers, students, and visiting scholars who would have access to controlled technical data, and signing off on the license or license exception relied on.
  • Approving technology control plans (TCPs) that restrict physical, visual, and electronic access to controlled technology and technical data within a specific lab or project, tying together the classification determination and the personnel who are cleared to work with it.
  • Serving as the point of institutional accountability if DDTC or a federal investigator has questions about a specific export, disclosure, or voluntary self-disclosure the institution has filed.

None of that work has to be performed personally by the Empowered Official end to end — most institutions have an export control office or research security office that does the operational screening, classification research, and TCP drafting. What 120.67 requires is that final sign-off and verification authority sit with someone who meets all four criteria, and that this person’s authority to say no is real, not nominal.

Why an inadequately empowered “Empowered Official” is a real institutional exposure

ITAR violations carry civil penalties, administrative penalties including debarment from future defense-related contracting, and — for willful violations — criminal penalties under the AECA, regardless of whether the violation was caught by DDTC, self-disclosed, or surfaced in an audit. If an institution’s designated Empowered Official does not actually meet the 120.67 criteria — because they lack real organizational authority, were never given written empowerment, or were never briefed on AECA/ITAR penalties — the institution’s export license applications and self-certifications rest on a defective foundation even if no individual export was itself improper. This is a documentation and governance gap that shows up in DDTC compliance visits and in due-diligence review during federal contract audits, and it is inexpensive to fix compared to the exposure it creates: formal written designation, a documented understanding of the regulatory scope and penalties, and confirmed independent authority to refuse a request.

Checklist for research institutions

  • Confirm the person holding the Empowered Official title is a direct employee in a genuine policy/management position — not a contractor, and not someone without real standing to refuse a request.
  • Put the delegation in writing. A title on an org chart is not the same as being “legally empowered in writing,” which 120.67(a)(2) specifically requires.
  • Document AECA/ITAR-specific training, separate from general research-compliance or restricted research onboarding.
  • Confirm the Empowered Official’s independence is real: can they decline to sign a PI’s or dean’s requested license application without professional consequence? If the honest answer is no, the appointment doesn’t meet the regulatory bar.
  • Appoint at least one Alternate Empowered Official who independently meets all four criteria, for continuity when the primary is unavailable.
  • Keep the DDTC registration (Form DS-2032) current with the correct named Empowered Official(s) — a stale registration listing someone who has left the institution is a common, easily-avoided finding.
  • Coordinate the role with the institution’s broader export-control program — see The Four Pillars of Export Control Compliance for how the Empowered Official function fits alongside technology control, travel screening, foreign-talent disclosure, and training.

Frequently asked questions

Can a university’s general counsel serve as the Empowered Official?

Yes, provided they meet all four 120.67 criteria: direct employment in a policy/management position, written empowerment to sign DDTC submissions, documented understanding of AECA/ITAR penalties, and genuine independent authority to refuse a request. General counsel and associate general counsel are common choices precisely because they typically already have the organizational standing the role requires — but the title of “general counsel” alone does not satisfy 120.67; the written empowerment and demonstrated regulatory knowledge still have to be in place.

Is the Empowered Official personally liable for ITAR violations?

Export control enforcement generally runs against the registrant organization, but individuals — including Empowered Officials — can face personal civil or criminal liability under the AECA in cases involving willful violations, particularly where the individual knew about a violation and failed to act on the authority the role requires them to hold. This is one of the reasons the role is deliberately assigned to someone with real authority rather than treated as a title of convenience.

Can one person be the Empowered Official for multiple campuses or research units?

Yes, if the DDTC registration structure supports it and that person genuinely has authority across all the covered units. Institutions with decentralized research operations across multiple campuses more commonly appoint a primary Empowered Official plus one or more Alternate Empowered Officials aligned to specific units, rather than requiring a single person to have practical authority everywhere.

Does every university need an Empowered Official?

Only institutions that register with DDTC because they manufacture, export, or broker ITAR-controlled defense articles, services, or technical data need to designate one. An institution whose federally sponsored research falls entirely within the fundamental research exclusion, and that does not otherwise handle USML-controlled items or technical data, may never trigger a DDTC registration requirement at all — though many research-intensive universities register defensively because some subset of their sponsored research, equipment, or DoD-funded projects does bring them into scope.

How is the Empowered Official different from whoever runs the technology control plan?

The Empowered Official has sign-off and verification authority at the institutional level, including for DDTC filings. Day-to-day technology control plan administration — badge access lists, lab-specific restrictions, training records for personnel cleared to access controlled technology — is usually run by export control office staff or a lab’s own compliance coordinator, with the Empowered Official approving the plan and remaining the accountable signatory rather than personally managing its daily operation.

For the broader institutional program this role sits inside, see The Four Pillars of Export Control Compliance, Export Control (EAR/ITAR) and International Research Collaboration, and ITAR US Munitions List (USML): What It Is and How It Applies to University Research. For the separate, broader federal research-security role, see NSPM-33 Research Security Program Requirements and “Covered Individual” Under NSPM-33.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →