Christopher Salmon clearBorder CEO in dark blazer and white shirt against white background

Christopher Salmon

Chief Executive

Executive summary

The National Security and Investment Act reflects a broader shift in how governments assess strategic capability, ownership, investment, and control. For organisations in defence and other sensitive sectors, NSI compliance begins before a transaction is announced. Is your organisation equipped to recognise an NSI risk before regulators do?

Key insights

  1. National security risk is often created operationally before it is assessed legally.
  2. Procurement, supplier onboarding, investment, and technology partnerships carry implications that shape national security exposure and commercial outcomes.
  3. Businesses need governance that identifies NSI exposure before formal transaction points, to reduce regulatory risk, protect strategic capability, and avoid costly intervention later.
  4. Who ultimately controls your strategic capability? Who can access it? Who stands to benefit from it?
  5. If regulators examined your ownership, investment, and supplier relationships today, what questions would they ask first?

The biggest mistake businesses make with NSI is assuming it starts when an acquisition is announced. In reality, by that point, most of the decisions that create national security risk have already been made.

A supplier has been selected, and a technology partnership agreed. An investor has been introduced. Data access has been granted; commercial teams have started moving. Governance is then asked to catch up with a risk that has already been created.

“National security risk is created operationally long before it is assessed legally.”

The National Security and Investment Act is usually viewed through the lens of acquisitions and investment. Increasingly, that picture is incomplete. For firms involved in aerospace and defence, advanced manufacturing, AI, quantum, critical infrastructure, communications, data, and other strategic sectors, NSI is better understood as evidence of a wider shift: that governments are asking harder questions about who owns, controls, accesses, funds, and benefits from strategic capability.

Why this matters

NSI compliance is more than a transaction issue. This is because governments assess how strategic capability is governed before ownership changes formally occur. Businesses in strategic sectors need strong governance structures to identify issues early, avoid regulatory delay, protect commercial relationships, and demonstrate control when scrutiny does arise.

Governance advisory on international trade →

Facing a customs, tariff or compliance challenge?

Get clear, actionable answers from a clearBorder trade specialist — book a free 30-minute call and leave knowing your next move.


Book your free consultation →

Governance begins before transactions

The strongest governance frameworks answer strategic questions before governments ask them. In practice, that means governance begins when:

  • Strategic suppliers are evaluated
  • Sensitive technology is shared with a potential partner
  • Overseas investment is discussed
  • Procurement teams choose a vendor with access to operational systems, technical information, or defence-relevant capability

“National security exposure isn’t created by the filing process, but by underlying commercial activity.”

Strong governance should identify NSI-sensitive issues before a transaction reaches legal review. In practice, that means organisations should ask:

  • How is strategic capability identified? Know where sensitive technologies, IP, data, software, and operational dependencies sit across the business.
  • Why does this matter? Decisions made during procurement, investment, partnerships, or supplier onboarding can create national security exposure long before lawyers become involved.
  • What are the risks of acting too late? Delayed transactions, regulatory intervention, additional scrutiny, costly restructuring, or commercial relationships that need to be revisited.
  • What are the biggest challenges? NSI-sensitive risk doesn’t sit within one function. It develops across procurement, legal, engineering, commercial, and executive decision-making, making visibility and coordination essential.
  • What does good governance look like? Clear ownership, early risk assessment, cross-functional communication, and enough visibility to recognise when routine commercial decisions may have national security implications.

Procurement becomes strategic

“Procurement decisions are no longer purely commercial.”

Supplier choice can create exposure around ownership, access, dependence, resilience, and technology control. A supplier may appear operationally attractive, commercially competitive, and technically capable; but if its ownership structure, jurisdictional exposure, or access to sensitive systems creates concern, procurement becomes a national security issue.

Procurement decisions determine who gains long-term access to strategic capability. A cloud provider may host sensitive engineering data. A software vendor may maintain systems supporting defence programmes. A specialist subcontractor may help develop sovereign technologies or critical components. What begins as a commercial relationship can ultimately shape operational resilience, technology control, and future regulatory scrutiny.

When it comes to strategic capability, governments are more interested than in previous decades in who can access it, influence it, maintain it, or become embedded within it over time.

Executive teams should therefore be asking:

  • Who ultimately owns this supplier?
  • Where is the technology developed, hosted, or maintained?
  • Who can access the data, source code, or technical information?
  • Could this supplier become strategically embedded?
  • Could this relationship create future NSI sensitivity?

Answering these questions has become especially crucial across defence supply chains, where software providers, engineering consultancies, semiconductor manufacturers, cloud platforms, specialist subcontractors, and data infrastructure providers may sit deep inside critical programmes.

In many cases, it is these relationships – not simply ownership – that determine where strategic capability ultimately resides.

Capital is not politically neutral

Capital carries strategic weight as well as commercial value. For businesses developing sensitive technologies, investment is a question of control, influence, access, and national resilience.

This is especially true where the business operates in sectors connected to sovereign capability, dual-use technology, AI, semiconductors, communications, cyber, energy, space, quantum, or critical infrastructure.

“The investor’s identity matters. So does their jurisdiction. So does their access to information, board influence, contractual rights, and long-term strategic intent.”

This does not mean investment should be viewed defensively by default, but that leadership teams must understand when capital introduces strategic questions, such as:

  • Who gains influence over strategic decisions?
  • Who can access sensitive technologies or information?
  • How may governance structures change?
  • Could an investment alter future regulatory scrutiny, government relationships, or access to defence programmes?

In a more contested geopolitical environment, governments are increasingly concerned with who controls strategic capability. Boardrooms should too – otherwise, investments intended to accelerate growth may create regulatory delay, restrict future opportunities, or raise national security concerns that are difficult to address retrospectively.

Once strategic influence has been created, it is considerably harder to unwind than it is to assess at the outset.

NSI changes how businesses should govern themselves

The practical lesson here? Organisations need enough internal visibility to recognise when business decisions might become NSI problems.

That requires governance across:

  • M&A and investment planning
  • Procurement and supplier onboarding
  • Technology transfers and partnerships
  • IP and data access
  • Export controls and licensing
  • Board and shareholder rights
  • Critical customer or programme dependencies

These issues rarely sit neatly in one function: legal may own transaction risk. Procurement may own supplier risk. Finance may own investor conversations. Technical teams may own access to sensitive capability. Commercial teams may own partnerships.

NSI-sensitive risk can form in the gaps between those functions. That makes it a governance issue, not simply a legal one.

What we learn in NSI

“NSI is just one example of a shift in how strategic businesses are thinking about control.”

For decades, open investment, global supply chains, international collaboration, and cross-border ownership were treated largely as engines of efficiency and growth.

They still can be. But in strategic sectors, they now sit inside a more contested environment. Governments increasingly ask:

  • Who owns it?
  • Who controls it?
  • Who can access it?
  • Who benefits from it?
  • Who could disrupt it?

Beyond formal transactions, these questions increasingly apply to suppliers, investors, technologies, partnerships, software, data, and operational dependencies. NSI compliance is therefore less a legal checkpoint than an expression of embedded corporate governance.

Ultimately, NSI doesn’t change how acquisitions are reviewed, but it does represent a change in how organisations should think about control.

For leadership teams, the question is this: is your governance capable of identifying strategic risk early enough to stay ahead of it?

Borders For the Boardroom:

Episode 15 | Defence export agreements

Hear from the clearBorder team on how firms can best prepare as new agreements come into force.

Listen now on Spotify →

Listen now on Apple →

 

Other interesting reads

Defence

Digital alliances, and how data became the connective tissue of modern defence

Modern defence capability depends on trusted digital alliances. As data, AI, cloud platforms, and shared engineering environments become central to defence programmes, organisations must understand the digital relationships that shape capability, sovereignty, and long-term strategic resilience.
Digital alliances, and how data became the connective tissue of modern defence
Defence

De-risking defence: where diversification meets export controls

Diversification can strengthen resilience, but it also creates new regulatory and geopolitical risks. Defence organisations that understand the export control and compliance implications of every new partnership can expand with greater confidence while protecting long-term strategic capability.
De-risking defence: where diversification meets export controls
Defence

FDI screening and the future of defence investment

Foreign investment is no longer judged on commercial value alone. As governments strengthen scrutiny of strategic industries, boardrooms must consider how investors, ownership structures, and sources of capital will be viewed through the lens of national security. Understanding geopolitical exposure alongside commercial opportunity is becoming a core part of good governance.
FDI screening and the future of defence investment