
AI for Parts & BOM Management
A practical look at what DFARS 252.246-7007 requires, how AS5553 and AS6081 differ, which detection methods actually catch counterfeit parts, and where traceability closes the gap.
·
⏱
9 min read

Michelle Ben-David
Michelle Ben-David is a mechanical engineer and Technion graduate. She served in an IDF elite technology and intelligence unit, where she developed multidisciplinary systems integrating mechanics, electronics, and advanced algorithms. Her engineering background spans robotics, medical devices, and automotive systems.

BOTTOM LINE
A DFARS-compliant detection and avoidance system needs three things working together, not one. It needs the documented process elements the clause spells out, including GIDEP screening and reporting. It needs a testing regime that can withstand an AS5553 or, for open-market buys, an AS6081 audit, since visual inspection alone catches only the crudest fakes. And it needs traceability that connects procurement, PLM, and quality history so a suspect part number gets flagged before purchase rather than after failure. Detection catches what traceability missed. Traceability is what keeps the detection queue from growing in the first place.
A counterfeit electronic part rarely announces itself. It is sanded, relabeled, or pulled from a scrapped board and resold as new, and in many cases it functions long enough to pass incoming inspection and clear a design review before it fails in the field. The US Government Accountability Office found 526 suspect counterfeit part reports filed with the Department of Defense between fiscal years 2011 and 2015 alone, and Customs and Border Protection seized more than 1.5 million counterfeit semiconductors at US borders between 2008 and 2010. Those numbers describe parts that were caught. The ones that were not have shown up in F-15 flight control computers, F-16 targeting systems, and a Navy helicopter radar, according to a Senate Armed Services Committee investigation.
For a contractor selling into the defense supply chain, or a manufacturer trying to keep counterfeit risk out of any electronics-heavy assembly, the practical question is not whether counterfeiting is real. It is what a compliant detection and avoidance system has to contain, which standards an auditor will check it against, and where traceability actually closes the gap that inspection alone cannot.
What Counts as a Counterfeit Electronic Part, and Why It Passes as Real
A counterfeit electronic part is one misrepresented in its identity, origin, or history, whether or not the misrepresentation was intentional at every step of the resale chain. That definition covers more than crude fakes. It includes a used part cleaned up and sold as new, a lower-grade part relabeled as a higher-grade one, and a part salvaged from a scrapped assembly with its date codes altered to look current.
The techniques behind these parts are specific enough to have their own vocabulary. Blacktopping sands off the original surface finish and repaints it to hide remarking. Die salvaging pulls a working die from a decommissioned board and repackages it. Leads get re-attached, and packaging gets reprinted with a different part number or manufacturer's logo entirely. None of this shows up in a datasheet comparison, because the counterfeit part is often built to look and, for a while, behave like the part it is impersonating.
Counterfeit incidents reported to the Department of Commerce grew from 3,868 in 2005 to 9,356 in 2008, and defense investigators later found the scale went well beyond isolated cases: one broker alone moved more than $15.8 million in counterfeit computer parts over four years before customs seizures caught up with the pattern. The parts that make it through are the ones a routine visual check was never going to catch, because a reclaimed or relabeled part is often built from real silicon that performs correctly on day one and fails only later, under thermal cycling or vibration the original grade was rated to survive and the counterfeit was not.
IN PRACTICE
It surfaces the relevant internal material, previous design decisions, past calculations, and backs everything with a cited source I can actually click on and verify.
- Yuval F., Clalit
What DFARS 252.246-7007 Actually Requires of a Detection and Avoidance System
DFARS 252.246-7007 applies to contractors subject to Cost Accounting Standards, and it does not ask for a general anti-counterfeiting policy. It specifies a system with defined elements: personnel training, inspection and testing against documented acceptance and rejection criteria, processes to prevent counterfeit parts from proliferating once suspected, tracking of parts from the original manufacturer through government acceptance, and management of the suppliers a contractor buys from under the related clause 252.246-7008.
The system also has to define how suspect parts get identified and quarantined, stay current with published counterfeiting trends and techniques, flow the same requirements down to every subcontractor tier, and control the use of obsolete parts so authentic, qualified stock gets prioritized over whatever is easiest to source. Two elements carry real reporting weight. Contractors are required to screen the Government-Industry Data Exchange Program, GIDEP, and credible-source alerts before a part is accepted, and they are required to report to both the contracting officer and GIDEP itself as soon as a part is suspected of being counterfeit, not only once it is confirmed.
A 2016 GAO review of how this actually played out found the enforcement side was uneven. The Defense Logistics Agency and the Navy applied different evidence thresholds for what counted as a suspect part, DOD had not finalized how it would assess whether a contractor's detection system met the clause, and restricted access to counterfeit reports kept some of the pattern from reaching the wider industry. Those findings were closed out through updated guidance by 2022, but they are a reminder that a documented system, not a general commitment, is what an audit is checking against.
AS5553 and AS6081: The Standards a Detection System Gets Measured Against
DFARS 252.246-7007 tells a contractor what its system has to cover. SAE AS5553 is one of the standards most audits use to check whether it actually does. First published in 2009 and now in its fifth revision, AS5553E from November 2025, it sets out avoidance, detection, mitigation, and disposition requirements for manufacturers and the broader supply chain, and each revision has extended flow-down requirements a tier further and sharpened the traceability language.
AS6081 covers the same territory from a narrower angle. It was written specifically for independent distributors buying components on the open market rather than direct from an authorized channel, where the counterfeit risk is highest because there is no manufacturer relationship to verify against. A contractor buying primarily through authorized distribution measures itself against AS5553. One that also sources through the open market, often to fill a shortage or obsolete part gap, needs a program that can also stand up to AS6081.
The distinction matters in practice because it is exactly where the GAO's 2016 findings bit hardest: a detection system built only for authorized-channel purchasing does not automatically cover an open-market buy made under schedule pressure, and that is the purchase most likely to need the extra scrutiny AS6081 describes.
Detection Methods That Separate Real Screening From a Visual Once-Over
Visual inspection under magnification is the starting point, and it catches the crude cases: inconsistent lettering, wrong font, mismatched date codes, or surface texture that does not match a known-good sample. It does not catch a part that has been properly blacktopped or a die that was pulled from a genuine, functioning source.
X-ray inspection and X-ray fluorescence spectroscopy look inside the package, checking internal construction against a known-good reference and confirming material composition where RoHS compliance is in question. Decapsulation goes further, removing the packaging entirely to examine the die markings and laser etching under a microscope, which is the only way to confirm the die inside actually matches the part number printed outside. Scanning acoustic microscopy finds internal delamination or voids that indicate a part has been reworked, and parametric or electrical testing checks the part's actual performance against its datasheet rather than trusting the label. For the highest-risk microcircuits, the Defense Logistics Agency requires botanical DNA marking at the point of authorized manufacture, which gives a forensic way to confirm a part's origin later in the chain.
None of these methods works alone, and that is the point of running a layered program rather than a single gate. The THAAD missile system absorbed a $2.675 million repair after a counterfeit part was found in its systems, and a Navy SH-60B helicopter radar and Air Force F-15 flight control computers both turned up counterfeit parts that had passed whatever screening was in place at the time. Each of those parts likely cleared at least one inspection step before it was caught, or was never caught at all until failure.
Traceability Is the Layer That Prevents the Need for Detection
Every method above answers the same question after the fact: is this specific part real. Traceability answers a different, earlier question: has this part number, from this supplier, ever triggered a GIDEP alert or a nonconformance report anywhere in the organization, and is there a documented chain of custody back to the original component manufacturer at all. That question is only answerable if procurement history, GIDEP screening records, approved-source lists, and prior quality reports are actually connected to the part number an engineer is about to specify, and in most organizations they live in separate systems that do not talk to each other: an ERP for purchasing, a PLM or PDM for the BOM, and a quality system for nonconformance history.
Leo AI works as an intelligence layer on top of those systems rather than replacing any of them, connecting to an organization's existing PDM, PLM, ERP, and document stores so a chain-of-custody question about a part does not require pulling three people from three departments into a call. Because it draws on data already tracked and cited, an engineer checking a supplier or a specific date code gets an answer sourced back to the actual record, not a guess, and can follow that citation back to the underlying document rather than taking the summary on faith, the same shift toward connected, citable part data already underway in AI BOM management more broadly.
That kind of traceable answer is also what separates a documented detection and avoidance system from a policy binder nobody consults under deadline pressure, which is exactly the condition the GAO's 2016 review found kept counterfeit parts moving through the supply chain in the first place. A team under schedule pressure to fill a shortage is precisely the team most likely to skip a manual GIDEP search, and the least able to afford being wrong about it.
FAQ
Stop Chasing Part History Manually
See how Leo connects PDM, ERP, and quality data into one traceable answer.
Leo connects PDM, PLM, ERP, and quality systems so a part's sourcing history or prior nonconformance record gets a cited answer instead of a round of emails.
Schedule a Demo →
#1 New AI Software Globally - G2 2026
Enterprise-grade security
Trusted by world-class engineering teams
