CFIUS Risk Framework
Section 721 of the Defense Production Act of 1950, as amended (Section 721), authorizes CFIUS to review covered transactions to determine the effects of such transactions on the national security of the United States. Any determination of the Committee to suspend a covered transaction, to refer a covered transaction to the President, or to negotiate, enter into or impose, or enforce any agreement or condition with respect to a covered transaction (e.g., through a mitigation agreement), must be based on a risk-based analysis, conducted by the Committee, of the effects on the national security of the United States of the covered transaction, which must include an assessment of the threat, vulnerabilities, and consequences to national security related to the transaction. CFIUS must also determine that existing provisions of law, other than Section 721 and the International Emergency Economic Powers Act, do not provide adequate and appropriate authority to protect U.S. national security.
The Committee’s risk-based analysis must include credible evidence demonstrating the risk and an assessment of the threat, vulnerabilities, and consequences to national security related to the transaction. CFIUS’s regulations define these terms as follows:
- Threat is a function of the intent and capability of a foreign person to take action to impair the national security of the United States;
- Vulnerabilities are the extent to which the nature of the U.S. business presents susceptibility to impairment of national security; and
- Consequences to national security are the potential effects on national security that could reasonably result from the exploitation of the vulnerabilities by the threat actor.
Section 721(f) includes an illustrative, non-exhaustive list of statutory factors the Committee considers, as appropriate, in conducting its national security analysis of covered transactions. The President has elaborated upon and expanded these statutory factors in subsequent orders and memoranda, including Executive Order 14083 and the America First Investment Policy.
If the Committee determines to resolve the identified national security risk arising from a transaction through mitigation measures, such mitigation must be reasonably calculated to be effective, allow for verifiable compliance, and enable effective monitoring of compliance and enforcement.
CFIUS Risk Matrix
Based on the risk framework described above, CFIUS staff prepared a risk matrix that provides a high-level description of the most common categories of national security risk that CFIUS identifies in its review of foreign investment transactions and an illustrative list of sample mitigation measures CFIUS may use to address such risks. The matrix outlines considerations relevant to threat, vulnerability, and consequence across the following eight categories of national security risk: critical infrastructure; cybersecurity; information security; personal data security; product integrity; proximity concerns; supply assurance; and technology transfer.
Parties are encouraged to review the risk matrix in their preparation of transactions and may submit a pre-filing consultation to engage with the Committee.
Click here to view the CFIUS risk matrix.
CFIUS staff share this matrix for informational purposes only. Nothing in the matrix constitutes legal, professional, or investment advice. The simplified risk categories and sample mitigation measures shown in the matrix are illustrative, non-exclusive, and non-exhaustive in nature and should not be construed as a final position, policy, commitment, or recommendation. This matrix does not impose any obligations on, or limit any rights of, any of CFIUS, the U.S. Department of the Treasury, or the U.S. Government. CFIUS makes no representation as to its judgment regarding the sufficiency of the sample measures in the matrix to mitigate any national security risk arising from any individual transaction and may, in its sole discretion based on CFIUS’s individualized assessment of the national security risk arising from a transaction, propose mitigation terms that are materially different from those shown in the matrix, or forego proposing mitigation terms and refer a transaction to the President with a recommendation to prohibit the transaction.