The impossible trap of being compliant with explicitly contradictory laws

I heard a great line from Miriam Wickertsheim 美丽洋: “Both sides are behaving professionally. They just have different ideas on what professional means.” (If you’re not following her on LinkedIn and/or Youtube, you should be.)

What’s professional? What’s required? What’s expected? What’s legal? While some of these questions are standard compliance questions, when working with China, the answers are not always what you might think. And if we’re being honest, sometimes the “cultural” questions aren’t being asked at all. This is usually the problem with compliance and audits—what you think is being or should be done is not what your local counterparts are thinking or doing.

First, The Compliance Trap—with whom should you be compliant? 

The US restricts the import of materials containing cotton from Xinjiang, yet China does not allow the exclusion of Xinjiang cotton from China-based supply chains. There are similar issues in France/China supply chain regulations as well as in other countries. The US has the UFLPA. China has three separate laws (Anti-Foreign Sanctions Law, “Blocking rules,” and the Unreliable Entity List). Throw in protectionism and sprinkle a bit of nationalism on top and you can see how this is a toxic recipe for international companies.

You might think, “Well, I’m not working with cotton so I’m safe.” But it’s not just cotton. It’s tomatoes and grapes (yea, well I don’t do foodstuffs either, I hear you saying), and PVC—sorry, everyone’s using that. And then there are solar panels, coal-products, and semiconductors that are all in a similar bind. Many fashion and food companies are either in court or have been questioned by their governments over these issues—PVH, Uniqlo, Zara, SMCP, Skechers, Nestle, Del Monte, Unilever, Whole Foods, and many others.

So, with whom do you comply? The issues around cotton were dealt with immediately by the Chinese public internet vigilantes—boycotting brands in the Chinese market that were boycotting Xinjiang cotton in their exports. Most other companies were either called to speak with their respective foreign governments and/or quietly and quickly got out of the sourcing from Chinese suppliers business. A huge task to do, even without time or social pressures, and not something everyone can do.

Further, in addition to social pressures, you can be exit-banned within China if you pick any country other than China first. If you’re based in China and have no other supplier (no China +1), you will be asked to make an impossible choice.

This is literally the singularly best argument for getting your supply chain out of China. And just because you’re not in currently affected industries doesn’t mean you won’t be—ask the guys from Manus—finding out too late that you can’t leave the country or that you can’t export your product is literally a death sentence.

If you have not already, you must resolve this potentially business-ending dilemma now! Find additional suppliers outside of the PRC ASAP! And by the way, SRI can help you with that.

Second, The Due-Diligence Blackout

While supply chain audits are common, far fewer companies, especially smaller ones, are looking at their data processes. Are you doing an information audit? Where is your data stored and how is it serviced (who is managing the flow)? Who has access in that process? What third parties are you using, or unknowingly giving access, to your data? Who is translating for you?

Since 2023 when foreign corporate intelligence firms were kicked out of China, the ability to investigate Chinese corporate counterparts became nearly impossible. Under the guise of national security, China eliminated the ability of foreign companies to do legal due diligence on Chinese entities. The Chinese reasoning is an expanded definition of espionage. The non-PC reason is that since 2017 all companies are required to allow for CCP cells included in their governing structures. And since most companies of any significance also have some form of government backing, corporate intelligence means Chinese government intelligence. Remember, in China “private” companies can be more than 50% owned by government entities, all bank loans are government approved, and local government approvals often include a political role including investment by local pension funds. 

That degree of corporate involvement by multiple levels of government means that any corporate due diligence report will ultimately lead to investigations into government individuals and enterprises being investigated by foreign intelligence firms; this is an unacceptable risk in China.

You have to have boots on the ground to resolve this concern. No other option. Period. You need to have your own people who are connected and in contact with local government offices and standards bodies. You need to know who your supplies are and who their suppliers are. Your logistics chain must be 100% transparent.

This is difficult and takes time, effort, local language and relationships, and money. Don't think otherwise.

Third, What an Audit Actually Finds

I was talking with a US company about their processes in China and they were telling me about a supply-chain audit they did recently, trying to get away from some of their China-dependence. They realized that while they were compliant and secure in their manufacturing exposure in China, they were shocked at the amount of data that was exposed through their own employees!

They have Chinese employees in almost every position in China, only a few leadership and technical positions are filled by foreigners from their US HQ. All of those foreigners basically need 24/7 translation. Their secretaries, drivers, assistants, even family helpers, all know significantly more confidential information than employees in similar positions in the organization. And most know more than they should.

When they were running an audit to figure out what additional personnel they would need if they opened up a second office in another Chinese city, they quickly realized that the assistant to the CEO both knew everything about the company and was frustrated that she wasn’t being considered for a leadership position in the new office. Losing her would be difficult. Losing her to a competitor could be disastrous. 

Similarly, they usually used in-house people, but when necessary, they hired temp translators for some off-site gigs that the C-level people were participating in. These temps had access to paperwork and conversations that were highly privileged. And while NDAs were in place, they were next to impossible to control or enforce in China.

You need to be both cautious about who has access to your data and how/when it’s returned and legally protected. Translators and other necessary services often have unknowingly broad access to info that would otherwise be proprietary and controlled. Be mindful of this and take precautions.

Selective Diversification

So, if you can’t do due diligence on your (prospective) counterparts, what do you do? China has the world’s best supply chains, leading infrastructure, and turnaround times that are second to none. You likely cannot not be doing business here. The question isn’t what to do instead of China, but rather how to manage what you allow to be done in China. That includes both manufacturing and information management.

Selective diversification is the watchword—how much can you afford to do elsewhere? Many companies try to have a secondary office run interference between China and foreign-based HQ. Previously, that intermediary was typically in Hong Kong. No longer.

Selectively moving component manufacturing out of China is another option. Moving to India, Vietnam, or Thailand might solve some of your location issues, but China limits what you can physically move to India (Apple) and your new partners in ASEAN countries are likely subsidiaries of your prior Chinese firm or their competitors (who you chose not to work with the first time around). Depending on the country, as much as 60-80% of all businesses in ASEAN are Chinese-owned!

Along those lines, data security is a priority issue in any audit. Thailand is a popular choice for data management with a host of new centers coming online every month (and 47 unregistered centers coming under investigation just this month!). Problem is, again, that many of those centers are Chinese owned. For example, Alibaba, ByteDance, Galaxy are all investing billions (with a B) in data centers in BKK. Being wary of who owns your data center isn’t racist, it’s a problem because of the leverage that the Chinese government can put on Chinese citizens in or out of the country via their family/investments/assets and the Chinese laws previously mentioned.

The Next Audit Question: Your AI Policy

Finally, last week’s Anthropic Security report should give everyone pause. The use of AI in the workplace by everyone for everything from weapons to corporate espionage means that if you don’t have a very specific AI policy and means of enforcing it in multiple countries, you’ve likely already lost control of your data.

China’s AI strategy, open models, is different from the US’s which means that use-cases are going to be different as well. Combined with data laws that require domestic storage, limited overseas control, allow for government access, and are all centered within a China first policy, and you have to be very careful before working with Chinese AI. Know this before going to China, not after you’re already there.