FOCI Mitigation: What the NRC Requires When There's Foreign Ownership, Control, or Influence
Foreign ownership doesn't automatically bar an NRC license — but it does trigger a specific mitigation review under the Atomic Energy Act. What that review actually looks for.
The business problem
The Atomic Energy Act and the NRC's implementing regulations at 10 CFR 50 restrict licensing of production and utilization facilities to entities that are not owned, controlled, or dominated by a foreign entity — but foreign investment, foreign board representation, or a foreign parent doesn't automatically disqualify a license applicant. It does trigger a foreign ownership, control, or influence (FOCI) review, and if FOCI is present, the applicant needs a mitigation structure the NRC finds acceptable before a license issues or continues.
Why it matters
FOCI mitigation isn't a one-time filing — it's an ongoing structure that has to keep functioning as ownership, governance, and personnel change. A structure that was acceptable at licensing can quietly stop reflecting reality as the company evolves — new foreign investors, a changed board composition, a foreign national placed in a role with access — without anyone revisiting whether the mitigation agreement still actually covers it.
“FOCI mitigation isn't a document you file once and put away. It's a structure that has to still be true on the day an NRC inspector asks about it — years after the ownership that triggered it may have changed.”
Signs the organization should pay attention now
- Foreign investment, a foreign parent, or foreign board members exist, and no one has documented whether a FOCI review was ever triggered
- A mitigation agreement exists but hasn't been reviewed since the ownership or governance structure last changed
- Foreign nationals are in roles with access to controlled technology or information without a documented review under the applicable mitigation structure
- Export control questions — Part 810 authorizations, ITAR, EAR — are handled separately from FOCI mitigation with no coordination between the two
- No one at the executive level owns confirming, on an ongoing basis, that the mitigation structure still matches actual ownership and governance
What good looks like
The organization treats FOCI mitigation as a living structure, reviewed whenever ownership, governance, or key personnel change, with export control touchpoints — 10 CFR Part 810, ITAR, and EAR where applicable — coordinated with the mitigation agreement rather than managed as a separate, unrelated workstream.
Score your FOCI mitigation structure in about 7 minutes.
Take the FOCI Mitigation AssessmentPractical guidance
Confirm whether a FOCI review was ever formally triggered and documented. If a mitigation agreement exists, check when it was last revisited against current ownership and governance. And put a named executive owner on the ongoing task of keeping the structure current — not just on the initial filing.
My CISO Partner's perspective
We treat FOCI mitigation as a standing governance obligation, not a licensing-stage checkbox — the organizations that stay current are the ones who assigned someone to keep checking, on purpose, long after the license issued.
Where to go from here
If a mitigation agreement exists but no one has checked it against the current ownership and board composition, treat that as an open finding — not a filed-and-forgotten formality.
Questions, answered directly.
No. It triggers a FOCI review, and if FOCI exists, generally requires an acceptable mitigation structure — disqualification is not automatic.
Commonly a Special Security Agreement, Voting Trust, or Proxy Agreement, among other approaches, depending on the degree and nature of the foreign involvement.
No. It's an ongoing structure that needs to be revisited as ownership, governance, and personnel change over time.
They're related but distinct — FOCI mitigation addresses licensing eligibility, while export control (10 CFR Part 810, ITAR, EAR) governs the transfer of technology and assistance to foreign persons. A comprehensive program coordinates both, which is also the focus of our separate FOCI Operational Controls assessment.
Talk to a CISO about your FOCI structure.
30 minutes. No obligation. No sales pitch.