Sample policy and compliance memo
CFIUS publishes a Risk Matrix setting out eight higher-risk transaction profiles and the mitigation terms
- Date:
- 29 July 2026
Executive summary
Treasury, acting as Chair of CFIUS, issued a public Risk Matrix identifying eight higher-risk transaction profiles: critical infrastructure, cybersecurity, information security, personal data security, product integrity, proximity concerns, supply assurance, and technology transfer. The framework applies the threat, vulnerability, and consequence approach in 31 C.F.R. § 800.102, and the listed mitigation measures are expressly illustrative and non-exclusive rather than a closed menu. The practical shift is a higher baseline for what transaction parties can now be expected to anticipate in diligence, filing strategy, and mitigation planning before engaging with the Committee.
Practical implications
- Screen the live transaction pipeline against all eight higher-risk profiles before deciding to decline a voluntary filing.
- Stress-test internally whether the business could operate under expensive mitigation measures, including governance restrictions, segregation of protected systems and data, source code review, vendor vetting, supply commitments, monitorships, and inspection rights.
- Use the new pre-filing consultation channel deliberately and with counsel, because early engagement can improve strategy but still carries disclosure consequences.