Norwegian Defence Industry Partners is highly structured, and rigorous on quality, full compliance and transparency. We hold to that on every supplier we represent, because it is how we earn trust and build relationships that stand the test of time.
In defence, the supplier you choose is a risk you take on: ownership you cannot easily see, integrity you cannot assume, quality and export status you have to prove. As Europe rebuilds its defence capacity, dependable, allied supply has become a strategic question, not a procurement detail.
NDIP exists to carry that risk as structure. We represent European component producers into the Norwegian defence supply chain as a commercial agent, and we stand behind every introduction with a documented governance, vetting and quality-assurance framework. For an intermediary in defence, that framework is not overhead on the business. It is the business.
NDIP is a commercial agent (handelsagent) under the Norwegian Agency Act, which implements EU Directive 86/653/EEC. We represent European defence-component producers under binding agency agreements and lead the commercial process on their behalf: qualification, specification support, negotiation and account stewardship.
We take no title, hold no stock, carry no guarantees, and are not a party to the supply contract. What the contractor gains is one accountable party in Norway that owns the relationship from first introduction to qualified delivery, and one party that has already vetted the supplier before any conversation begins.
Our remuneration is disclosed to all parties, our introductions are documented, and our suppliers pass the same gate regardless of how commercially attractive they are. In a sector where opaque intermediaries are the recurring integrity risk, transparency is the position we take, not a concession we make.
The framework assembles a proportionate system from standards a contractor's compliance function already recognises. Each obligation below is mapped to an owner and a control, and tracked, not assumed.
| Domain | Anchor standard / regime |
|---|---|
| Anti-bribery & integrity | ISO 37001; OECD Anti-Bribery Convention; UK Bribery Act; US FCPA; Norwegian Penal Code corruption provisions |
| Commercial agency | EU Directive 86/653/EEC; Norwegian Agency Act (agenturloven) |
| Export & import control | Norwegian Export Control Act and DEKSA; EU dual-use 2021/821; ITAR/EAR interfaces |
| National security / FOCI | Norwegian Security Act (sikkerhetsloven) and NSM clearance; EU FDI Screening Regulation 2019/452 |
| Sanctions & AML | EU, UN, OFAC and UK OFSI measures; Norwegian sanctions and money-laundering law |
| Quality assurance | NATO AQAP 2110; ISO 9001; NATO codification (NCAGE / NSN) |
| Cyber & data | ISO/IEC 27001; NIS2; NSM ICT principles; GDPR |
| Responsible business | Norwegian Transparency Act (åpenhetsloven); EU CSRD / CSDDD; OECD Guidelines; UN Guiding Principles |
Governance is founder-led with a deliberate separation of duties. The person who originates a supplier is never the sole person who clears it: elevated decisions require a named second signatory, the board or advisory reviews the framework annually, and counsel is engaged on integrity, export and agency questions. The system is organised into seven domains under a single governing policy, NDIP Corporate Governance.
| Domain | What it governs |
|---|---|
| A · Integrity & responsible business | Anti-bribery (ISO 37001-aligned), code of conduct, ESG, conflicts of interest, fee transparency, whistleblowing |
| B · Inbound vetting | Background checks and supplier due diligence bound into one tiered onboarding gate |
| C · Deal governance | End-use and anti-diversion control, portfolio conflict checks, documented introductions |
| D · Quality assurance | Supplier qualification against NATO AQAP / ISO 9001, codification, non-conformance handling |
| E · Cyber control | Information security for shared specifications and data; supplier cyber-posture screening |
| F · Ongoing monitoring | Continuous sanctions and PEP screening, re-vetting by tier, audit and management review |
| G · Compliance | Regulatory adherence map, registers, audit trail, the evidence pack for a compliance review |
The framework is risk-driven, not checklist-driven. We assess risk through three lenses, because we carry our own exposure and sit between two parties whose risks we must also manage: risk to NDIP, risk in the European partner, and risk to the Norwegian contractor. Every control maps to an identified risk, and every identified risk maps to a control. We hold near-zero appetite for integrity, export-control and end-use risk.
| Tier | Trigger | What it routes to |
|---|---|---|
| Green | All residual risks low; no gate concerns | Standard onboarding; annual re-vetting |
| Amber | A residual risk needs management, or a sensitive category is not fully cleared | Enhanced due diligence; second-signatory sign-off; recorded conditions; semi-annual re-vetting |
| Red | A high residual risk, or any knock-out gate is hit | Declined or blocked, and recorded |
Any one of these stops the relationship immediately, regardless of commercial value, and the decision is recorded.
Every supplier passes the same onboarding gate. Due diligence covers ownership and control, sanctions and integrity, quality qualification, cyber posture and export status. The result sets a risk tier, the tier sets the depth of sign-off, and nothing is onboarded on a single person's judgement where the risk is elevated.
Assurance does not stop at onboarding. Sanctions and PEP screening run continuously, suppliers are re-vetted on a defined cycle, and the governance state of every relationship is held as structured data, so a compliance review is answered with a current report rather than a manual reconstruction.
You deal with one accountable party in Norway. Every supplier we bring you has passed a documented vetting and anti-corruption gate before you meet them. Quality is evidenced to NATO AQAP and ISO 9001, cyber posture is screened, and sanctions screening never stops. And because every step is recorded, we can show your compliance function the work, not just assert it.
Secure, qualified, allied European supply at a time of constrained capacity, reaching you through a partner that has already absorbed the integrity, quality and security risk on your behalf. That is protection for the business, the operation and the board, and one fewer relationship you have to police yourself.
Our core governance policies are published in full. Open any of them here. We share the underlying vetting instruments and the full register with registered partners, and with a contractor's compliance function on request.
Framework alignment: ISO 37001; ISO 9001 / NATO AQAP 2110; ISO 27001; GDPR; Norwegian Agency Act (agenturloven); Norwegian Transparency Act (åpenhetsloven); OECD Guidelines / UN Guiding Principles.
This is the top-level governing policy of NDIP's governance system. It sets the purpose, the roles and decision rights, the risk methodology, and the register of policies beneath it. Where this policy and a subordinate policy conflict, this policy governs.
Purpose. To establish how NDIP is governed so that it operates as a trustworthy, auditable commercial agent in the defence supply chain, and can evidence that to the primes and principals it works with.
Scope. This policy and the policies beneath it bind all NDIP personnel, officers and the Board; anyone acting for NDIP; and NDIP's conduct toward principals, Norwegian contractors, public officials and third parties. It applies to all NDIP activity in all territories in which it operates.
NDIP is a commercial agent (handelsagent) representing European defence-component producers into the Norwegian defence supply chain under binding agency agreements. It takes no title, holds no stock, gives no guarantees, and is not a party to the supply contract. Because a paid intermediary in defence is the highest-scrutiny profile in business ethics, governance is the condition of market entry, not overhead.
NDIP governance is organised into seven domains under this policy, in a hierarchy: Corporate Governance, then policies, then procedures and playbooks, then instruments, then registers. The seven domains are:
At current scale roles are compressed, but this policy requires separation of duties on acceptance decisions: the person who originates a principal is never the sole person who clears it.
Risk acceptance is tiered by rating and cannot be delegated downward:
| Rating | Acceptance authority |
|---|---|
| Low | Managing Director / risk owner |
| Medium | Managing Director |
| High | Managing Director with Second Signatory sign-off; Board notified |
| Critical | Board / Second Signatory with counsel |
Board approval is required for: adoption of and material change to this policy and any policy beneath it; acceptance of any high or critical residual risk; ISO 37001 certification decisions; and entering a country or product area outside the current scope.
Risk is assessed through a three-lens model (risk to NDIP, risk in the partner, risk to the contractor) using probability multiplied by the highest consequence dimension, with a controls-to-risk traceability chain. Every control required by a policy beneath this one must trace to an identified risk. The scored assessment is published separately as NDIP's risk overview.
The following policies and instruments are adopted under this governing policy:
The framework is built out in phases across the seven domains, with quality-assurance, cyber-control, monitoring and compliance instruments added as NDIP scales. Conflict, gifts-and-hospitality, decision and vetting registers are maintained as the evidence base.
This policy and each policy beneath it are reviewed at least annually by the Board, and on any material change in operations, threat or regulatory environment. Compliance is evidenced through the registers and reported to the Board at the governance forum.
Framework alignment: ISO 37001; OECD Anti-Bribery Convention; UK Bribery Act 2010 (s.7); US Foreign Corrupt Practices Act; Norwegian Penal Code (straffeloven) §§387–389; EU Whistleblower Directive 2019/1937.
This policy establishes NDIP's anti-bribery management system, aligned to ISO 37001 and proportionate to a founder-led commercial agent operating in defence. We publish it in full and make it available to the principals and contractors we work with.
NDIP has zero tolerance for bribery and corruption in any form, in the public or private sector, direct or through a third party, anywhere it operates. For a commissioned intermediary in defence this is not only a legal obligation but the condition on which the business can exist. NDIP commits to act with integrity and full transparency, and to maintain an anti-bribery management system aligned to ISO 37001.
This policy binds all NDIP personnel, officers and the Board; anyone acting for or on behalf of NDIP; and all NDIP dealings with principals, contractors, public officials, intermediaries and other third parties.
Prohibited conduct. Bribery, kickbacks, secret commissions and trading in influence are prohibited. Defence is the highest-enforcement sector under the OECD Convention, the UK Bribery Act and the US Foreign Corrupt Practices Act, and a single proven instance, or a credible allegation, would end NDIP's access to the primes whose own compliance regimes forbid working through compromised intermediaries.
Facilitation payments. Facilitation ("grease") payments are prohibited. Small payments to expedite routine official action are illegal under the UK Bribery Act and Norwegian law, and are a common entry point to enforcement.
Gifts, hospitality and expenses. Gifts and hospitality must be reasonable, proportionate, transparent and never intended to influence.
Principal and counterparty due diligence. Anti-bribery due diligence is performed on every principal before onboarding and on relevant counterparties. NDIP's principals and their owners are the third parties through which bribery risk would most likely reach it, and due diligence is the control that keeps a compromised counterparty out.
Commission integrity and fee transparency. NDIP's remuneration is legitimate, proportionate, documented and fully disclosable. The single most effective control for the commissioned-intermediary concern is that NDIP's income is defensible and transparent; pure success-contingent, undisclosed commissions are the pattern that enforcement and primes distrust.
Conflicts of interest. Conflicts of interest are identified, disclosed and managed.
Donations, sponsorships and political contributions. NDIP makes no political contributions. Charitable donations or sponsorships are permitted only with Managing Director approval, must not be a disguised bribe or linked to a business advantage, and are recorded. Any donation above EUR 1,000 requires Board approval.
Raising concerns (whistleblowing). Anyone may raise a concern about bribery or corruption safely and without retaliation.
Training and communication. All NDIP personnel receive anti-corruption awareness on joining and at least annually; principals are made aware of NDIP's anti-corruption stance at onboarding; this policy is available to all personnel and to counterparties.
Monitoring, records, audit and sanctions.
Anti-corruption risk is treated as a near-zero-appetite category: treatment is mandatory and a confirmed instance is a hard stop, regardless of commercial value. Acceptance of any residual anti-corruption risk follows the decision-rights table in NDIP's Corporate Governance policy; elevated residual risk requires Second Signatory or Board sign-off.
Framework alignment: ISO 37001; OECD Guidelines for Multinational Enterprises; UN Guiding Principles on Business and Human Rights; Norwegian Transparency Act (åpenhetsloven); GDPR; Norwegian Agency Act (agenturloven).
NDIP's value is trust, and this Code states the standards of conduct that protect it. We publish it in full and make it available to the principals and contractors we work with.
This Code applies to all NDIP personnel, officers and the Board, and to advisers, contractors and any future sub-agents acting for NDIP. Everyone in scope is expected to read it, to follow it, and to raise concerns when something looks wrong. It sits beneath our Corporate Governance policy and is read alongside the Anti-Bribery & Corruption Policy and the ESG Policy.
We act with integrity, we are transparent, we comply with the law, we put trust before the transaction, and we contribute to a secure, resilient and sovereign European defence base. We never use fear, secrecy or improper influence to win business.
Integrity and honesty. We are truthful with principals, contractors and authorities. We do not misrepresent products, qualifications, prices or our own role. We do not make promises we cannot keep, or imply influence we do not have.
Compliance with the law. We comply with all applicable law in every territory in which we operate: anti-corruption, sanctions, export control and end-use rules, competition law, agency law (agenturloven), and data protection. Where the law and this Code differ, the stricter standard applies.
Conflicts of interest. We identify, declare and manage conflicts of interest. We hold to a one-principal-per-niche rule so that we never represent competing component lines, we declare personal or financial interests that could affect our objectivity, and we step back where that objectivity could reasonably be questioned. The detail is set out in the Anti-Bribery & Corruption Policy.
Confidentiality and data protection. We protect the confidential information entrusted to us, in particular contractors' specifications and pricing and principals' technical data, on a need-to-know basis and under our information-security controls. We process personal data lawfully under the GDPR. We never use information from one party to another's disadvantage.
Fair dealing. We deal fairly with principals, contractors, competitors and suppliers. We compete on merit and structure, never on inducements or disparagement. We honour our commitments and our documented introductions, and we do not seek unfair advantage through manipulation or concealment.
Responsible business and human rights. We expect ourselves, and the principals we represent, to respect human rights and decent working conditions, and we screen for it. We hold firm red lines on end-use and will not enable improper or diverted end-use. The detail is set out in the ESG Policy.
Respectful, safe workplace. We treat colleagues, counterparties and the people we vet with respect, without discrimination or harassment, and we maintain a safe working environment, consistent with the Norwegian Working Environment Act (arbeidsmiljøloven).
Company assets and accurate records. We use NDIP's assets, including the market database, only for legitimate business purposes, and we protect them. We keep accurate and complete records of introductions, fees and decisions, and we do not create false or misleading records.
Raising concerns. Anyone may raise a concern in good faith without fear of retaliation: to the Managing Director or, where the concern involves the Managing Director, to the Chairman acting as Second Signatory, or to the Board. We take concerns seriously, investigate them proportionately, and protect those who raise them.
All NDIP personnel confirm that they have read and will follow this Code on joining and at each annual review. The principals and contractors we work with are made aware of it.
Framework alignment: Norwegian Transparency Act (åpenhetsloven); OECD Guidelines for Multinational Enterprises; UN Guiding Principles on Business and Human Rights; UN Global Compact; EU CSRD / CSDDD (awareness); Arms Trade Treaty (context).
NDIP operates in defence, where responsible business is not a soft topic: it concerns who we represent, what they make, and where it ends up. This policy sets out how NDIP meets its responsible-business obligations and screens the principals it represents. We publish it in full.
To set NDIP's commitments on human rights, responsible supply, ethics, the environment and governance, and the standard to which it screens the principals it represents. It applies to NDIP's own conduct and, through the vetting gate, to the principals it brings to Norwegian contractors. It reflects NDIP's positioning: contributing to a secure, resilient and sovereign European defence base, which is itself a responsible-business stance.
NDIP aligns to the OECD Guidelines for Multinational Enterprises and the UN Guiding Principles on Business and Human Rights as its responsible-business baseline, meets the due-diligence and transparency duties of the Norwegian Transparency Act (åpenhetsloven), and tracks the EU CSRD and CSDDD as they apply. Defence-specific conduct is informed by the Arms Trade Treaty principles on responsible transfer.
Human rights and decent work. NDIP respects internationally recognised human rights and expects the same of its principals.
Responsible supply chain and principal selection. NDIP chooses the principals it represents responsibly, not only commercially.
Business ethics and anti-corruption. Responsible business begins with integrity. NDIP operates to its Anti-Bribery & Corruption Policy and Code of Conduct; anti-corruption and fee transparency are treated as core governance commitments, not separate from them.
Defence-sector responsibility: end-use and responsible transfer. NDIP will not enable improper end-use, diversion, or transfers contrary to allied values. This is where a defence agency's responsibility is sharpest: enabling an improper end-use or a diversion would be a legal breach, a reputational catastrophe, and a direct harm to the contractor. NDIP's "European resilience and sovereignty" stance is also a screening filter: a reason to decline business, not only to win it.
Environment. NDIP keeps its own footprint low, as a light services business, and notes environmental performance in vetting where material. NDIP does not overstate its environmental credentials.
Governance, transparency and reporting.
This policy is owned by the Managing Director, overseen by the Board, and reviewed at least annually and on any material change.