Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / Jurisdictions / United States

Country file

United States

The transatlantic relationship is substantial. The US context requires separately verifying the contract, the entity's DPF status and the impersonation risks specific to B2B relationships.

Relationship with the European Union

Transatlantic relationship — no blanket audit relief

The relevant mechanism here may be the Data Privacy Framework, but only for participating US companies; supplier requirements remain specific to the contract and the sector.

Sources reviewed on 14 August 2026

01

Economy and sectors

02

Incidents, fraud and impersonation

03

Points to check within your organisation

To be verified

Data Privacy Framework status

Check the receiving entity, its active participation and the scope covered; never extend it automatically to the group.

To be strengthened

Supplier instructions and payment

BEC specifically targets supplier relationships and payments: a contact register, an independent callback and dual validation can all be demonstrated.

To be tested

AI-assisted impersonation

Procedures must withstand a convincing email, voice or profile: the trusted channel takes precedence over the realism of the message.

Developments to be aware of

The topics that may change your answers

Email compromise

BEC is tracked separately from generic phishing because it directly affects client–supplier relationships.

FBI IC3, 2025 annual report
What this means for your situation

For a US supplier, the distinctive challenge is to align technical evidence with a robust B2B trust protocol. The DPF addresses certain transfers; it covers neither the integrity of client instructions nor the defensibility of a security response.

Official sources

Confidential exchange

Describe your European relationship and the request received.

Contact iKNSA