If a supplier will access your sites, systems or sensitive information, look beyond its trading name and price. Foreign ownership, control or influence screening examines who can direct the business and whether that creates an exposure you need to manage.

Look beyond the supplier’s name: Understand ownership; Examine control and influence; Assess access and consequences.
Screen proportionately and revisit material changes.

What foreign ownership control or influence actually means

Foreign ownership, control or influence describes a supplier relationship where a party outside the country — a government, a company or an individual — has the ability to affect the supplier's decisions in ways that could work against your interests, even without a majority shareholding. The concept originated in defence and national security procurement, where the concern is direct: a supplier with sensitive access whose decisions could be directed by a foreign government is a different risk than one that simply happens to have foreign customers or investors.

The reason this now matters well beyond defence contractors is that the same structural questions apply anywhere a supplier has privileged access — to critical infrastructure, to sensitive data, to physical sites, or to a supply chain a regulator or a major customer expects you to have visibility over. In Australia, entities responsible for identified critical infrastructure assets carry supply chain risk management obligations under the Security of Critical Infrastructure Act; the practical implication for procurement is the same regardless of the exact legal trigger — you need a process for asking these questions, not just a policy that says you should.

Ownership is the easy part; control and influence are not

Screening for FOCI is often reduced, incorrectly, to a single question: who owns this company? That is necessary but not sufficient. Three distinct mechanisms can put a supplier under foreign influence:

A supplier can be locally incorporated, majority locally owned, and still carry meaningful FOCI exposure through the second or third mechanism. Screening that stops at a company registry search checks the easiest box and misses the two harder ones.

None of this makes foreign ownership, control or influence automatically disqualifying. Global supply chains mean a large share of legitimate, capable suppliers will show up with some FOCI exposure once you look properly. The purpose of screening is to make that exposure visible before contract signature, so it can be managed through proportionate contractual controls, rather than discovered afterwards when a change of ownership or an incident forces the question.

A screening procedure that fits inside procurement, not beside it

FOCI screening only works if it is built into the existing procurement workflow rather than run as a separate, occasional exercise:

  1. Tier suppliers before you screen them. Not every stationery supplier needs the same scrutiny as a vendor with access to your operational technology network. A two-tier approach — full FOCI screening for suppliers above a defined risk threshold, a lighter check for the rest — keeps the process sustainable.
  2. Establish beneficial ownership, not just the registered entity, using ownership disclosures, corporate registry searches and, where the tier warrants it, a request for the supplier to disclose its own ownership structure directly.
  3. Ask about governance, not just ownership: board composition, any external veto or approval rights, and whether key decisions require sign-off from a related entity elsewhere.
  4. Ask about financial dependence: concentration of revenue with a single foreign customer or parent, and significant debt held by an external party.
  5. Cross-check against sanctions and export control lists relevant to your jurisdiction and the supplier's, as part of the same screening pass rather than a separate compliance step done later.
  6. Record the result and the decision, including for suppliers cleared with no material findings — an undocumented "we checked and it was fine" is not evidence the check happened.
  7. Re-screen on a cycle and on trigger events — an acquisition, a change of major shareholder, or a new contract that expands the supplier's access are all reasons to re-run the check outside the normal schedule.

Worked example: a fictional water utility screening a SCADA vendor

A fictional regional water utility, Bindarra Water, was sourcing a new vendor to support its SCADA environment — a tier-one supplier under its own risk tiering, given the access involved. The screening surfaced that the vendor, though locally incorporated and locally staffed, was a wholly owned subsidiary of an offshore parent company, with three of five board seats held by parent-company nominees and standard contractual terms requiring parent approval for any change of ownership or major subcontracting arrangement. None of that made the vendor unusable — plenty of legitimate technology vendors operate this way — but it changed the conversation from "approve on price and delivery" to "approve with named contractual controls on data handling, subcontracting disclosure and incident notification," decided with the FOCI exposure on the table rather than discovered afterwards.

Common mistakes in FOCI screening

FOCI screening sits inside a broader supply chain risk program, and it works best once you already have the fundamentals in place — see How to Build Your First Risk Register (Free Starter Pack) if supplier risk isn't yet being tracked anywhere formal. If your organisation is exchanging threat or vulnerability information with suppliers or partners as part of this process, handling classification correctly matters — see Free TLP Wall Chart for Your Security Operations Centre. And if you're being asked by a customer or regulator to demonstrate your supply chain risk data in a structured, machine-readable format, What Is OSCAL, and Does Your Organisation Need It? covers where that requirement is heading.

Get the policy and procedure

SRMBOK's Procurement and Secure Supply Chain Policy and Procedure gives you both governance documents together — a procurement and secure supply chain policy and a supplier risk assessment procedure — covering export controls, sanctions, FOCI, cyber baselines, sole-source justification, modern slavery and ESG, with two-tier risk tiering and seven-year retention built in.

Adapt the example tiering and retention periods to your organisation. Sanctions, export controls, ownership screening and record-retention obligations depend on the jurisdictions, activities and contracts involved; have the responsible specialists confirm the applicable requirements. A template does not establish compliance.