The due diligence assessment is rewritten as eight risk-based subjects
What the document says“assess, using a risk-based approach as appropriate-- ``(i) the cybersecurity practices of a small business concern; ``(ii) patent analysis; ``(iii) employee analysis; ``(iv) foreign ownership of a small business concern seeking an award”
Subsection (a)(3)(A) rewrites subparagraph (A) of subsection (vv)(2) of section 9 of the Small Business Act. As rewritten it names eight subjects to assess using a risk-based approach as appropriate: cybersecurity practices, patent analysis, employee analysis, foreign ownership of the applicant firm including the financial ties and obligations of the firm and its employees to a foreign country, person or entity, which are to include surety, equity and debt obligations, foreign affiliations of a covered individual, owner or other key personnel with an entity in a foreign country of concern, investment relationships with an individual or entity in such a country, technology licensing agreements or joint ventures including joint venture-like agreements with such an individual or entity, and business relationships between a covered individual, owner or other key personnel and such an individual or entity.
What the document actually says“assess, using a risk-based approach as appropriate-- ``(i) the cybersecurity practices of a small business concern; ``(ii) patent analysis; ``(iii) employee analysis; ``(iv) foreign ownership of a small business concern seeking an award”
The agency sizes up each firm. It weighs how big the risk is first. It looks at how the firm guards its computers. It looks at its patents, its staff, and who abroad owns part of it.
This is a background check on the firm. Eight things are named to look at. Some are about money from other countries. Some are about deals with groups abroad.
No action is recorded against this proposal. That is not evidence that none has been taken, and nobody has yet read it against the record. See what the tracker does not yet cover.