Counterfeit Parts Risk Assessment (AS5553 / DFARS)
This free counterfeit parts risk assessment helps electronics, aerospace, and defense manufacturers measure their exposure to counterfeit electronic components, aligned to SAE AS5553 and the DFARS counterfeit prevention clauses. Ten questions cover the full defense-in-depth chain: prevention planning, authorized sourcing, verification testing, obsolescence management, traceability, inspection training, containment, GIDEP reporting, flowdown, and contract review. You receive a risk band with specific mitigations. Counterfeit components cause field failures in safety-critical hardware, and under DFARS the cost of rework and replacement is unallowable - meaning one escape can consume the margin of an entire program.
1. Do you have a documented counterfeit parts prevention plan (per AS5553, AS6174, or equivalent) appropriate to your products?
2. What fraction of your electronic components is purchased from OEMs or franchised/authorized distributors with full supply chain traceability?
Independent distributor and broker purchases are where the overwhelming majority of counterfeits enter the supply chain.
3. When you must buy from independent distributors or brokers, what verification testing is applied?
4. How do you manage component obsolescence, the primary driver of high-risk sourcing?
5. Can you trace every electronic component in a shipped assembly back to its source and purchase documentation?
6. Are incoming inspection personnel trained to detect counterfeit indicators (blacktopping, sanded markings, refinished leads, inconsistent date codes)?
7. What happens when a suspect counterfeit part is found?
Under DFARS and AS5553, suspect parts must be contained and must not be returned to the seller, since returned parts re-enter the supply chain.
8. Do you report suspect counterfeits to GIDEP and monitor GIDEP alerts against your inventory and BOMs?
9. Are counterfeit prevention requirements flowed down to your subcontractors and contract manufacturers?
10. Does your contract review process identify counterfeit-prevention obligations (DFARS 252.246-7007/7008, customer clauses) and their cost impact before bidding?
How the risk model works
The assessment scores your program across the layered-defense model that AS5553 formalizes: keep counterfeits out (sourcing and obsolescence questions), catch what gets in (testing, training, and traceability questions), and limit the damage when something is found (containment, reporting, and flowdown questions). Each layer is scored 0-3 and the layers are deliberately balanced, because real-world escapes almost always involve failures in at least two layers - a pressured broker buy plus inspection that was not looking for the right indicators, for example. A strong front door with weak traceability still lands you in the moderate band, because the cost of an escape is determined by how fast you can bound it.
The industry numbers behind the questions
The weighting of the questions reflects well-established supply chain data:
- The overwhelming majority of counterfeit incidents trace to parts bought through independent distributors and brokers rather than OEM or franchised channels
- Obsolescence is the dominant root cause - counterfeiters concentrate on EOL parts because buyers of obsolete components have the fewest alternatives and the most urgency
- GIDEP receives hundreds of suspect counterfeit reports annually, and reported parts frequently reappear from other sellers, which is why returning suspect stock for credit is prohibited practice
- Under DFARS 231.205-71, the cost of counterfeit parts and their rework or replacement is unallowable on covered contracts unless strict conditions (including timely GIDEP reporting) are met
Turning your band into a mitigation plan
Sequence mitigation by where counterfeits actually enter. If you scored low on sourcing and obsolescence, fix those first - an authorized-only default with a controlled exception path eliminates most exposure at zero capital cost, and a BOM health program removes the urgency that drives risky buys. Testing and training investments come second: a risk-based protocol applied only to non-authorized buys concentrates spend where risk lives, typically a few hundred to a few thousand dollars per suspect lot versus six-figure escape costs. Traceability and reporting are your insurance layer - build them before you need them, because reconstructing lot genealogy during a live suspect-part investigation is exponentially harder than recording it at receiving. Reassess after any surge in EOL notices or new contract manufacturer.
How Netray hardens your supply chain systems
Counterfeit prevention runs on data your ERP already touches: approved source lists, lot and date-code capture at receiving, certificate-of-conformance document links, and BOM-to-inventory genealogy. Netray implements these controls natively in Infor SyteLine, LN, and Baan - authorized-source enforcement at PO entry, mandatory lot traceability, quarantine workflows that block suspect stock from allocation, and one-click where-used analysis that maps a suspect lot to every affected order and shipment. Our on-prem AI adds proactive monitoring: BOM obsolescence risk scoring, GIDEP alert screening against your live inventory, and anomaly detection on sourcing patterns, all without your parts data leaving your environment.
Frequently Asked Questions
We only buy from big-name distributors. Do we still need a counterfeit prevention program?
Yes, for three reasons. First, AS9100 clause 8.1.4 and DFARS flowdowns require a documented process regardless of your current sourcing mix. Second, sourcing discipline erodes under schedule pressure - the risky broker buy happens precisely when a line-down situation meets an obsolete part, and without a controlled exception process it happens invisibly. Third, your contract manufacturers and sub-tier suppliers buy components too, and their sourcing is your exposure unless you flow down and verify requirements.
What testing should we require on broker-sourced parts?
Follow a risk-based protocol aligned to AS6081 or IDEA-STD-1010: external visual inspection under magnification, marking permanency (resistance to solvents), X-ray for die and bond-wire consistency, XRF for lead finish composition, decapsulation of samples to verify the die, and electrical testing against the datasheet. The depth should scale with application criticality and lot value - flight or safety hardware justifies the full battery at an accredited lab, while a commercial-grade lot may warrant a subset. Always test before parts enter usable stock.
Are we required to report suspect counterfeit parts to GIDEP?
If you are a contractor covered by DFARS 252.246-7007, reporting suspect counterfeit electronic parts to GIDEP within 60 days is required, and timely reporting is also a condition for cost allowability protections. Beyond the mandate, reporting is how the industry defends itself - GIDEP alerts let other manufacturers screen the same seller and part before their own escape. Coordinate reports with your legal counsel and customer, quarantine the parts, and never return them to the seller.
Take the assessment now and find out whether your supply chain would keep a counterfeit component out of your next shipment.
Related Tools
Aerospace Supplier Scorecard
Rate a supplier across 10 criteria - OTD, quality escapes, AS9100 status, FAI performance, CAPA responsiveness, compliance flowdown, and financial health - for an instant risk rating.
Aerospace & DefenseAS9100 Audit Readiness Checklist
A 30-point checklist for AS9100 Rev D certification and surveillance audits, weighted toward the aerospace-specific requirements where auditors write the most findings.
Aerospace & DefenseFirst Article Inspection (AS9102) Checklist
A 30-point checklist for complete, first-pass-acceptable AS9102 FAIs - planning, Form 1/2/3 completeness, characteristic accountability, and the delta FAI triggers teams miss.
Go Deeper
DoD AI Adoption in 2026: What It Means for Defense Manufacturers
DoD AI adoption in 2026: what CDAO programs, budget priorities, and new acquisition rules mean for defense manufacturers planning their own AI investments now.
AI Governance for Export-Controlled Data (ITAR/EAR)
AI governance for export-controlled data: policies, access controls, and audit trails that keep ITAR and EAR data out of public LLMs and off foreign servers.