Compliance & Quality
Compliance is the product
A supplier that cannot document control status, end-user, and provenance is a risk to the program. These are the controls we run and the evidence we produce.
Export control program
An Empowered Official owns export determinations and holds authority to stop any shipment. Ironvale is registered with the Directorate of Defense Trade Controls; the registration is on file and renewed annually. Classification, licensing, and recordkeeping follow written procedures. Personnel receive export training on hire and annually thereafter, with additional briefings when a rule change affects our commodities.
Anti-corruption
We comply with the Foreign Corrupt Practices Act and the UK Bribery Act. Facilitation payments are prohibited without exception, including where local practice tolerates them. Third-party agents, freight partners, and in-country brokers are screened for beneficial ownership, political exposure, and prior enforcement action before appointment, and are re-reviewed annually. Contracts with agents include audit and termination rights.
Sanctions screening
Counterparties, end-users, consignees, and financial intermediaries are screened against OFAC SDN and sectoral lists, the Consolidated Screening List, EU restrictive measures, and UN sanctions lists. Records are rescreened daily; any match or near match places the transaction on hold pending compliance review. Embargoed destinations are refused.
Supply chain integrity
We purchase through OEMs and authorized distributors. Certificates of conformance are collected and delivered with the shipment. Where franchised sourcing is unavailable for an electronic part, additional inspection and test referencing AS6081 is quoted and performed, and the customer is informed before award. Lot, serial, and shelf-life data are captured at pack-out.
Quality
The quality management system is built to ISO 9001:2015, with AS9120 as the target scope for aviation spares distribution. Nonconformances are contained and reported within one business day. Root cause analysis and corrective action are documented, with effectiveness verified before closure.
Cybersecurity
Controlled unclassified information is handled under NIST SP 800-171. A self-assessment is complete and the score is posted in SPRS. DFARS 252.204-7012 is accepted and flowed down to suppliers who handle CUI. CMMC readiness activity is tracked against the level required by our customers' contracts.
Human rights and conduct
We do not supply units or organizations subject to credible reports of gross violations of human rights. We cooperate with end-use monitoring, including Blue Lantern checks. Our security-related activity references the Voluntary Principles on Security and Human Rights. Employees and partners are required to report concerns; retaliation is prohibited.
Ethics hotline
Concerns can be reported to ethics@ironvale-dl.com, anonymously if preferred. Reports are reviewed by the compliance function and, where the report concerns compliance leadership, by outside counsel.