August 22, 2026

Conflict Armament Research iTrace: Intelligence Source Guide

0

Conflict Armament Research sends investigators into conflict zones to physically document recovered weapons and ammunition, record their markings, and formally trace them back through the export chain. iTrace is the resulting record of how legally manufactured arms end up in the wrong hands.

conflict-armament-research-itrace-intelligence-source-guide

Conflict Armament Research sends investigators into conflict zones to physically document recovered weapons and ammunition, record their markings, and formally trace them back through the export chain. iTrace is the resulting record of how legally manufactured arms end up in the wrong hands.

At a glance

Source Conflict Armament Research iTrace
Category Conflict, Crime & Human Security › Military, Weapons & CBRN
Homepage https://www.conflictarm.com/itrace/
Format HTML
Access Restricted — eligibility-gated (member states, institutions or vetted users)
The platform catalogue records this as open. That is wrong, and the correction is explained under Access, licensing and what you may do with it below.
Disciplines Weapons Intelligence, Geospatial Intelligence
Mission domains Weapons Trafficking

Field-traced illicit weapons & ammunition. — as catalogued in the platform’s own source registry.

iTrace is the global weapon reporting mechanism built and operated by Conflict Armament Research, a UK-headquartered investigative organisation founded in 2011. Its method is unusual and is the whole point of the source: CAR field teams travel to conflict-affected areas, work with national authorities and armed forces who have recovered materiel, and inspect items physically. They photograph and record what is stamped on the metal – manufacturer marks, model designations, serial numbers, ammunition headstamps with factory codes and production years, lot and batch numbers, proof marks, and the component-level markings on improvised explosive devices and unmanned systems. Those physical identifiers are then used to submit formal trace requests to the manufacturing state and to states in the export chain, who may confirm the original sale, the authorised end user and the transfer date. The output is a chain: this rifle was made here in this year, exported to that state under that authorisation, and recovered from this group at this location on this date. iTrace holds those records with their supporting documentation, and CAR publishes findings as investigative reports, thematic studies and periodic digests on its website.

Every other arms-transfer dataset works from paperwork. SIPRI models transfers from open reporting; the UN Register collects what states choose to declare; customs data records what was declared at a border. All of them describe the legal trade and infer the illicit one. iTrace is the only systematic source that starts from the physical object at the end of the chain and works backwards. That inversion is what makes it analytically irreplaceable for WEAPINT and for the GEOINT question of where materiel actually is rather than where it was sent. It produces two things nothing else does: the point of diversion, meaning the identifiable link in a legal supply chain at which materiel left authorised custody, and the diversion time lag, meaning how long elapsed between a lawful export and the item's appearance in a conflict. Those two variables are the substance of arms control enforcement. Without them, an arms embargo investigation can establish that a group has weapons but cannot establish who is responsible for their being there.

Who publishes it, and why that matters

CAR is an independent investigative organisation, not an intergovernmental body, and its funding for iTrace has come principally from the European Union through Council Decisions under the Common Foreign and Security Policy, with support from individual states. That structure has consequences worth understanding. The EU funding gives CAR the resources to sustain field deployments that no NGO could otherwise afford and gives its trace requests standing with national authorities, which is why states answer them. It also means the geographic scope of iTrace is shaped by where the EU has policy interest and where CAR can obtain access from a cooperating national authority – which is not the same as where diversion is worst. CAR's leverage depends entirely on the cooperation of the governments who hold the recovered materiel and of the manufacturing states who answer the traces, so its reporting is constrained by relationships it has to maintain. The organisation has been consistently willing to name exporting states in its findings, including EU member states, which is the strongest available evidence that the funding relationship has not compromised the output. Programme funding is renewed in phases, so the continuity of the collection is a political decision taken periodically rather than a permanent arrangement.

Provenance is the first question to ask of any dataset and the one most often skipped. Who collects it, what their incentive is, whether they publish a methodology, and whether they correct the record when they get something wrong all bear directly on how much weight a finding drawn from it can carry.

What a record actually contains

The fields you will be working with, what each one means, and whether it is something you can pivot on. Read the meanings carefully — more analysis is wrecked by misreading a field than by failing to find one, and a field that looks like an observation is often an inference.

Field Type What it means Pivot value
item_type enum What the documented object is – small arm, light weapon, ammunition, ordnance, IED component, unmanned aerial system, or dual-use component such as a microcontroller or motor. The distinction matters because the tracing method and the legal framework differ for each. Materiel class, applicable control list entry, and the relevant transfer regime.
make_and_model string Manufacturer and model designation as marked on the item, recorded as observed rather than as interpreted. Where markings are absent or ambiguous CAR records that fact rather than assigning a probable identification. Manufacturer entity, production facility, and the family of related items from the same producer.
serial_number string The unique identifier stamped on a weapon, which is the key to a formal trace with the manufacturing state. Publication of serial numbers is handled carefully because they can identify individuals in the custody chain. Formal trace request; matching to national firearms registries and to seizure records held by other authorities.
headstamp string The marking on the base of a cartridge case, typically a factory code and a production year, sometimes with calibre and lot information. For ammunition this substitutes for a serial number and is the primary identifier. Producing factory, production year, and by inference the state and period of manufacture.
lot_or_batch string Production lot or batch identifier, present on packaged ammunition and on ordnance. Lot data is what allows a single recovered item to be tied to a specific consignment rather than to a factory in general. Consignment-level tracing, which is a far stronger evidentiary link than factory-level attribution.
country_of_manufacture string The producing state, established from markings and confirmed through the trace where the manufacturer responds. Note that assembly, licensed production and re-export all complicate this and CAR distinguishes them. Export control jurisdiction; the state that holds the authorisation records.
date_of_manufacture int Production year, usually from the marking. Combined with the recovery date this yields the interval within which diversion must have occurred, which is the backbone of the diversion time-lag analysis. Temporal bounding of the diversion window.
documented_location string Where the item was physically inspected, at a granularity that varies with operational security and with what the holding authority permits. This is the recovery or custody location, not necessarily the location of use. Geospatial correlation with conflict event data, control-of-territory mapping and supply route analysis.
documentation_date timestamp When CAR's investigator inspected the item. It postdates recovery, sometimes by a long interval, and it is not the date of any incident in which the item was used. Timeline placement; the outer bound on when the item was in the recovering party's custody.
recovering_or_holding_party string The force or authority from whom CAR obtained access to the item. Determines what the record can and cannot say about who was using the materiel, and is a source of selection bias that must be carried into any analysis. Actor entity; the partner relationship that made the documentation possible.
transfer_chain array The sequence of established transfers from manufacture onwards, populated only where states have answered a trace. Frequently partial – a chain that stops at the first export is common and is itself a finding. Exporting state, authorised end user, brokers and intermediaries where identified.
point_of_diversion string The identified link at which materiel left authorised custody, where CAR has been able to establish it. This is the single most consequential field in the dataset and the hardest to populate. Accountable state or entity; the basis for embargo enforcement and for sanctions designation.
evidence_reference string Pointer to the supporting photographic and documentary record behind an entry. The photographs of markings are the actual evidence; the database entry is an index to them. Verification of a claim; the material a court or panel of experts would need to see.

Coverage — and what is not in it

Conflict-driven and access-driven rather than global. CAR has deployed across sub-Saharan Africa, the Middle East, North Africa, parts of Asia and, since 2022, extensively in Ukraine, and its regional emphasis follows both the intensity of conflict and the willingness of a national authority to grant access to recovered materiel. Coverage is deepest where a cooperating government holds large quantities of captured materiel and permits inspection, which biases the record towards conflicts with a state or coalition partner on the documenting side. Materiel types have widened substantially over time: the early work concentrated on small arms and ammunition, and more recent investigations cover IED components, commercial electronics diverted into weapons systems, unmanned aerial systems and their subcomponents, and dual-use goods subject to export controls. The temporal record runs from CAR's founding in the early 2010s to the present, with the documentation density increasing markedly as the iTrace programme has been renewed and expanded. Publication cadence is irregular and event-driven – major investigative reports appear when an investigation concludes, and thematic and periodic outputs fill the intervals. The database itself is updated as field documentation and trace responses arrive, which is a continuous but uneven process.

Known blind spots

Absence of evidence here is not evidence of absence. These are the conditions under which Conflict Armament Research iTrace will not show you something that is nevertheless real:

  • Everything depends on someone recovering the materiel and letting CAR see it, so weapons that remain in active use, that are held by a party CAR cannot approach, or that are recovered by a government unwilling to cooperate are simply absent from the record.
  • The recovering party is usually a state or a state-aligned force, which systematically biases the sample towards materiel captured from their opponents and away from materiel diverted by or to themselves.
  • Traces only produce answers when states respond, and non-response is common; a chain that terminates at the manufacturing state's silence looks identical in the data to one where no trace was attempted, unless the record is read carefully.
  • Items with obliterated, absent or never-applied markings cannot be traced at all, and these are over-represented in exactly the trafficking streams that matter most.
  • Craft-produced and locally manufactured weapons have no legitimate supply chain to trace back into, so a growing share of conflict materiel falls outside the method entirely.
  • The absence of a state from CAR's findings reflects where CAR has worked and who answered traces, not the state's conduct – drawing a league table of diverting states from published findings inverts the selection process.
  • Documentation dates lag recovery, sometimes by months or years, so the dataset is a poor instrument for near-real-time questions about what is currently in circulation.
  • Publication is selective by design: sensitive findings may be reported to states or to UN panels without public release, and operational security constrains location precision, so the public record is a subset of what the organisation knows.
  • Ammunition headstamps identify a factory and a year but not a consignment unless packaging or lot data survives, so a large share of ammunition findings can attribute production but not the export that led to diversion.

Write the blind spot into the product. A statement that something “was not observed in Conflict Armament Research iTrace” is defensible; a statement that it “did not happen” is not, and the difference is what survives cross-examination.

Access, licensing and what you may do with it

Access model: Restricted — eligibility-gated: member states, accredited institutions or vetted users only

There are two tiers and the difference matters. CAR's investigative reports, thematic studies and periodic publications are freely available on conflictarm.com and are substantial documents – they contain the photographs, the marking data and the trace narratives, and for most analysts they are the usable product. The iTrace database itself is a restricted resource whose full functionality is intended for governments, international organisations and accountability mechanisms rather than for general public use, and access arrangements have changed as the programme has moved through funding phases. There is no public API. Confirm current access terms directly with CAR rather than relying on any secondhand description, because this is precisely the kind of arrangement that changes between programme phases. If you are working for a national authority, a UN panel of experts, or a sanctions body, approach through institutional channels – CAR's model is built on cooperation with exactly those users and a formal request is far more likely to succeed than an individual registration. For everyone else, plan on the report corpus as the source and build your collection around document ingestion.

Licence

CAR's published reports are made available for reading and citation, and the organisation's purpose is to have its findings used in policy, enforcement and accountability work – so citation with attribution is welcomed. That does not extend to wholesale reproduction of report content or of the photographic evidence, which remains CAR's property and in some cases is constrained by agreements with the authorities who granted access. Database content accessed under a restricted arrangement carries the conditions of that arrangement, which typically limit onward disclosure. There is a separate constraint that is ethical rather than contractual: serial numbers, precise recovery locations and identifying detail about cooperating personnel can expose individuals and can compromise CAR's future access, and republishing them because they appeared once in a PDF is irresponsible even where it is lawful. Confirm current terms with the organisation before building anything that redistributes their material.

Rate limits and fair use

Not applicable in the API sense – there is no programmatic interface to rate limit. The practical throughput question is document collection from the website, where politeness means a slow crawl, respect for robots directives, and caching everything you fetch so you never retrieve the same PDF twice. Publication volume is low enough that a weekly check is more than sufficient and a daily one is pointless. If you hold restricted database access, throughput is governed by the terms of that access and by the fact that the underlying records are produced by human investigators at human speed; there is no bulk export to be had and no reason to want one.

Licensing changes, and it changes without warning. A dataset that was free for research this year may not be free for commercial or evidential use next year. Confirm the current terms before you build a dependency on it, and record the terms you relied on alongside the data — the licence in force at the time of collection is part of the provenance.

Collecting it

How Conflict Armament Research iTrace is actually pulled, in the order you would set it up. Prefer the bulk or export interface over per-item lookups wherever one exists: it is kinder to the publisher, faster for you, and gives a reproducible snapshot rather than a series of point-in-time answers you cannot reconstruct later.

Method Format Cadence Notes
Report and publication corpus HTML Weekly polling for new items The primary accessible channel. Monitor the publications listing, capture each new report with its publication date, and store the PDF locally with a hash – CAR's reports are the evidence and they should be preserved rather than linked.
Full-text extraction of reports bulk On acquisition Run text extraction over the PDFs. The analytically valuable content – marking data, trace narratives, named entities, dates – is in the body and in figure captions, and none of it is exposed as structured data anywhere.
Structured extraction of materiel records CSV Manual, per report Build a local table of documented items from each report: type, make, markings, manufacture year, documentation location and date, established chain. This is analyst work, not scraping, and it is where the value is created.
iTrace database access HTML Per access arrangement For authorised institutional users. Query the underlying records directly rather than working from published summaries. Terms and functionality vary by arrangement and by programme phase.
Cross-referencing with UN panel reports bulk Per panel reporting cycle UN Panels of Experts publish materiel findings that frequently overlap with and corroborate CAR's, using comparable marking evidence. Collect them together; they are the same evidentiary tradition.

Ingesting it into the platform

Every step below is idempotent and cursor-based: interrupt one and it resumes from where it stopped rather than duplicating rows or losing progress. Collection is recorded per source, so a feed that quietly stops publishing shows up as a stale timestamp instead of silently thinning your coverage.

  1. Register as a document source, not a feed — Add CAR in sources.php as a low-cadence publication source and record in the description that the structured database is not held. This prevents a coverage claim the platform cannot back and sets analyst expectations correctly in source-catalog.php.
  2. Ingest reports as dated artefacts — Run collect.php against the publications listing and store each report with its publication date, title, and file hash through import.php. The document is the unit of record; treat the PDF as evidence and never discard the original in favour of extracted text.
  3. Extract entities to the platform's model — Resolve manufacturers, exporting states, brokers and armed groups named in reports to org-profile.php and actor-profile.php entities so that a company named in a diversion finding becomes a node rather than a string. This is what turns a report library into a graph.
  4. Structure the materiel records by hand — Create per-item records for documented materiel with their marking data, manufacture year, documentation location and date. Accept that this is manual analytical work; automated extraction from these reports produces errors on exactly the fields that matter most.
  5. Compute the diversion window — For each item, derive the interval between manufacture year and documentation date and store it explicitly. Aggregated across items this is the diversion time-lag distribution, which is the single most policy-relevant statistic the source supports and it is not published as a field anywhere.
  6. Link to conflict geography — Push documented locations into the country and theatre views and use correlate.php to align documentation events with conflict event data for the same area and period. Where materiel appears is a supply-chain fact; where it appears relative to fighting is an operational one.
  7. Build the supply-chain graph — Use link-analysis.php to express established transfer chains as relationships between manufacturer, exporting state, authorised end user and recovering context. The graph makes visible the repeated intermediaries that individual reports mention only once each.
  8. Carry the provenance and the caveat — Every derived record should retain a pointer back to the specific report and page it came from, and any product generated in reports.php should state that the underlying sample is access-driven. No relationship in this graph originates from a model – the only language-model function in the platform is Summarise in copilot.php, which writes prose about records that already exist.

Registered sources and their last-collected state are listed in sources.php, and the scheduled chain that keeps them current is in automation.php.

How it is wrong, and how to tell

Every dataset is wrong in characteristic ways. Knowing which ways is the difference between using a source and being used by one, and it is the part of source evaluation most often skipped because it is the part that takes work.

This is among the highest-quality evidence available in the arms control field, and the reason is methodological rather than institutional. The findings rest on physical inspection of objects by trained investigators who photograph what they record, and on formal trace responses from the states that hold the authorisation records. That is a chain of evidence with two independent anchors – the object and the paperwork – and it is far stronger than the inference-from-open-reporting that characterises most arms transfer analysis. CAR is also unusually disciplined about the boundary of its claims: reports distinguish what was observed from what was established by trace from what remains unresolved, and unanswered traces are reported as unanswered rather than papered over. The organisation's findings have been used by UN panels of experts and by national authorities, which is a meaningful external validation. The limitation is not accuracy but representativeness. Every record is true; the set of records is a convenience sample determined by access, and no amount of care in documentation fixes that. Judge individual findings as strong and aggregate statistics as indicative.

Characteristic false positives

  • Selection bias masquerading as a finding – the states and companies that appear most often in the published record are those operating in theatres where CAR has had access, and counting mentions produces a ranking of CAR's deployments rather than of diversion.
  • Country of manufacture is confused with responsibility for diversion; materiel is frequently diverted many transfers downstream of the producer, and naming the manufacturing state as the culprit is the most common misreading of this material.
  • Licensed production and re-export break the marking-to-origin assumption, so an item marked as produced by one country's design may have been made under licence elsewhere entirely.
  • Ammunition headstamp codes are not universally unique or fully documented, and codes have been reused, transferred between facilities and imitated, so a headstamp identification is a strong hypothesis rather than a certainty.
  • Documentation date is read as incident date, placing an item in a location years after it was actually recovered and generating spurious correlations with contemporaneous events.
  • An incomplete transfer chain is read as an established one – a chain that shows manufacture and first export tells you nothing about the diversion point, and the absence of further links is often the state's silence rather than the end of the story.
  • Small numbers of documented items are extrapolated to fleet-level claims about a group's arsenal, when the sample is whatever a partner force happened to capture and hand over.
  • Component-level findings on commercial electronics are over-attributed; a widely available microcontroller found in a weapon system indicates a control failure somewhere in a distribution network of thousands of intermediaries, not a deliberate transfer by the chip's manufacturer.

None of these make the source unusable. They make it a source that requires corroboration before an assertion built on it goes into a product, which is true of every source and admitted by few.

Ageing

Individual records do not go stale in the ordinary sense – a documented item with its markings and its established chain is a permanent historical fact and becomes more useful over time as it joins a larger pattern. What ages is the operational picture built from them. A finding that a particular route or intermediary was supplying a group describes a period, and routes shift quickly under enforcement pressure, so a supply-chain conclusion more than a year or two old should be treated as historical unless re-established. Trace results can also change: a state that did not answer may answer later, and a chain published as incomplete may be completed in a subsequent report, so a record's transfer chain is a snapshot of what was known at publication rather than a final state. The characteristic stale record here is a diversion pathway described in a report from several years ago, cited in current analysis as though it were still operating, with no check on whether the intermediary named in it still exists or the corridor is still open.

What this source feeds

A source is only worth what it lets you conclude. These are the disciplines that collect through it, the mission domains it serves and the data points it yields — every one is a tag, so you can follow any thread from here into the rest of the library.

Collected by these intelligence disciplines

Serves these mission domains

Yields these data points

How each sector uses Conflict Armament Research iTrace

The same dataset is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The records are shared — the constraints, thresholds and outputs are not.

🎖 Military and defence

For force protection and threat characterisation, iTrace answers the question of what an adversary is actually fielding rather than what it is assessed to have, and it does so at component level for the improvised and commercially derived systems that dominate contemporary conflict. Findings on IED components, drone subsystems and diverted commercial electronics feed directly into countermeasure development and into understanding an adversary's resupply dependencies – a group reliant on a single commercial component category is vulnerable in a way that is not visible from order-of-battle data. The material also supports the arms embargo enforcement mission where a force is operating under a mandate that includes it. The discipline is to remember that the sample comes from what partner forces captured, so the absence of a system type from the record is not evidence that the adversary lacks it, and CAR's access depends on being seen as an independent documenter rather than an intelligence collector.

🕵 National intelligence

This is the primary open collection route for WEAPINT questions about diversion, embargo violation and state sponsorship, and it produces evidentiary-grade material that can be used in settings where intelligence reporting cannot. The distinctive analytical product is the diversion pathway: not that a group has a weapon, but that the weapon left authorised custody at a specific point in a specific chain, which converts a capability observation into an accountability finding. That supports sanctions designation, demarche and public attribution in a way that few other sources can. For collection management, CAR's published record also maps the boundaries of what is documentable – the theatres and materiel classes where physical documentation is feasible – which is useful for deciding where other collection must carry the load. Treat aggregate patterns cautiously and individual chains as strong.

👮 Law enforcement

For firearms trafficking, organised crime and sanctions enforcement investigations, the value is the method as much as the data. CAR's marking-based tracing is the same discipline that national firearms tracing systems apply domestically, and its findings can identify the diversion points and intermediaries that a domestic investigation encounters at its far end. Where a case involves materiel with a conflict-zone origin, CAR's published record may already contain the chain you are trying to establish. Practical routes matter: formal cooperation with international tracing mechanisms and with the national authorities that answer traces is how this works, not direct approach to an NGO for evidence. Chain of custody for anything CAR documented rests with the authority that recovered the item, and CAR's record is investigative documentation rather than a seizure exhibit.

🔍 Private investigation and corporate security

Corporate investigators and compliance teams use this material for a specific and increasingly common problem: establishing whether a client's or supplier's products have appeared in conflict materiel. CAR's component-level findings on commercial electronics have named a large number of ordinary manufacturers whose parts reached weapons systems through distribution networks they did not control, and the resulting exposure is reputational, regulatory and sometimes contractual. The right use is diagnostic – map your distribution chain against the intermediaries CAR has identified and tighten where they overlap – rather than defensive. Be precise in client reporting about what a component finding does and does not imply, because the distance between 'your part was found in a drone' and 'you supplied a sanctioned entity' is large and easily elided in a summary.

📰 Journalism and OSINT media

CAR's reports are among the most citable documents in the arms trade field because the evidence is photographic and the reasoning is shown. For investigative reporting on arms transfers, embargo violations and the supply chains behind conflict weapons, they provide a documented starting point that stands up to legal review. The reporting discipline is to distinguish the three claim types the reports themselves distinguish: what was physically observed, what was established through a state's trace response, and what remains inferred. Headlines that name a manufacturing country as the source of a group's weapons usually collapse that distinction and misrepresent the finding. Approach CAR directly for context – the organisation engages with press – and be careful with serial numbers and precise locations, which can endanger the people who made the documentation possible.

🌍 NGO, humanitarian and human rights

For arms control, human rights and accountability organisations this is the evidence base that makes advocacy specific. Generic claims about irresponsible transfers move nobody; a documented chain from a named exporter to a named end user to a recovery in a conflict is the material that changes export licensing decisions and supports Arms Trade Treaty implementation arguments. It is also the substrate for accountability work: the same marking evidence that supports a diversion finding can support an investigation into unlawful attacks where remnants are recovered from a strike site. The handling responsibilities are real – documentation from conflict zones can identify cooperating individuals and communities, and republishing location and serial detail from a report without thinking through the consequences transfers risk onto people who are not your organisation's to expose.

🎓 University and research

The corpus supports research on diversion mechanics, the political economy of the arms trade, embargo effectiveness, and the emerging literature on dual-use component control in an era of commercially derived weapons. Its methodological transparency makes it unusually good teaching material for evidence standards in conflict research. The central research problem is the sampling frame: iTrace is a purposive sample determined by access negotiations, so any quantitative claim requires an explicit model of what determined inclusion, and comparisons across theatres or over time are confounded by changes in CAR's deployment pattern and funding phase. The most defensible research designs use iTrace records as case material and triangulate against customs data, SIPRI transfer estimates and UN panel findings rather than treating the database as a population. Research ethics review is warranted where records could identify individuals in conflict settings.

Playbook: working Conflict Armament Research iTrace end to end

A repeatable sequence from first pull to finished product. Each phase states what you are trying to establish, not merely what to click — the objective is a defensible chain of reasoning, not a completed checklist.

Phase 1 — Decide whether your question is about supply or about presence

If you want to know what an armed group is fielding right now, this source is slow and partial and conflict event data or imagery will serve better. If you want to know how the materiel got there and who is accountable, nothing else comes close. Most disappointment with iTrace comes from asking a currency question of a provenance source.

Phase 2 — Read the method before the findings

CAR publishes how it documents and how it traces, and understanding the difference between an observation, a trace response and an inference is a prerequisite for using anything in the reports. An analyst who has not internalised that distinction will produce claims the underlying evidence does not support, and the error will not be visible in their citation.

Phase 3 — Map the access geography first

List the theatres and time periods where CAR has actually deployed and with which partner forces. This is your sampling frame and every subsequent aggregate claim depends on it. Write it down explicitly, because the temptation to reason from published mentions to a global picture is strong and the resulting error is severe.

Phase 4 — Build the item table by hand

Extract documented materiel from reports into a structured local table – type, marking data, manufacture year, documentation location and date, established chain, and a pointer to the source page. Automated extraction fails on exactly the fields that carry the meaning. This step is slow and it is where the analytical value is created rather than merely retrieved.

Phase 5 — Establish the diversion window for each item

Difference the manufacture year against the documentation date to bound when the item must have left authorised custody. Aggregate these across a theatre and you have the diversion time-lag distribution, which distinguishes historical stockpile leakage – long lags – from contemporary supply, where recent production appears in a conflict within months.

Phase 6 — Trace the chain forwards, not backwards

Once a manufacturer and export are established, follow the chain forwards through the authorised end user to the point where accountability breaks. The forward direction is where the diversion point lives. Working backwards from the recovery tends to stop at the producer and produces the standard misattribution of blame to a manufacturing state that did nothing wrong.

Phase 7 — Distinguish stockpile diversion from deliberate transfer

Long lags, mixed production years and heterogeneous origins indicate leakage from a poorly secured national stockpile. Tight clustering on recent production years and a single origin indicates a deliberate contemporary supply relationship. These two conclusions carry completely different policy implications and the item table will separate them if you built it properly.

Phase 8 — Corroborate against panel and customs evidence

UN Panels of Experts publish materiel findings using the same evidentiary tradition and frequently cover overlapping ground. Customs and trade data can confirm that a transfer of the right description occurred at the right time. Agreement between independent methods is what turns a documented item into a defensible attribution.

Phase 9 — Handle component-level findings with proportionality

For commercial electronics and dual-use goods, establish how widely the component is distributed before drawing any conclusion about the supplier. A part sold through thousands of distributors tells you about the porousness of a distribution network; a part sold to a handful of customers tells you about a specific customer. Conflating these has produced published claims that did not survive scrutiny.

Phase 10 — Take the graph to the entities, not the documents

Push manufacturers, brokers, end users and armed groups into the platform's entity model so that repeated intermediaries across separate reports become visible as a pattern. A broker mentioned once in each of four reports is invisible in a document library and obvious in a graph, and those repeated nodes are usually the enforcement targets.

Phase 11 — Check whether the pathway is still open

Before using a supply route finding in current analysis, establish whether the intermediaries still exist, whether the corridor is still usable, and whether subsequent reporting has superseded it. Routes reconfigure quickly under enforcement pressure, and citing a three-year-old pathway as current is the most common way this source is misused.

Phase 12 — Write the sample caveat into the product

Any finished assessment should state which theatres and periods the underlying documentation covers, who the recovering parties were, and what the record therefore could not have shown. The strength of this source is that its limits are knowable; a product that does not state them discards that advantage and invites a rebuttal that would otherwise have been easy to pre-empt.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

What to pair it with

No single source carries a finding. These are the datasets that corroborate, extend or contradict this one — and a source that contradicts is worth more than one that agrees, because it is the only thing that will tell you when you are wrong.

Source Relationship What it adds
SIPRI Arms Transfers Database contradicts Models the legal international arms trade from open reporting. Where iTrace shows an item arriving somewhere it should not be, SIPRI shows what the authorised trade in that category looked like – and the discrepancy is the finding.
Small Arms Survey extends The standing research authority on small arms and light weapons, including stockpile security, craft production and marking practice. The conceptual framework most iTrace analysis sits inside.
UN Register of Conventional Arms corroborates State-declared transfers in seven major categories. Sparse and voluntary, but where a declaration exists it is the state's own admission of a transfer and can anchor a chain.
Arms Trade Treaty prerequisite The legal framework governing authorisation and diversion prevention. Understanding what states are obliged to assess before authorising an export is what makes a diversion finding actionable rather than merely interesting.
INTERPOL extends International policing cooperation including firearms tracing mechanisms that connect national registries. The route through which a law enforcement trace request actually travels.
ACLED corroborates Georeferenced conflict events. Aligning documentation locations against event data places materiel findings in the operational context that gives them meaning.
Oryx corroborates Open-source visual documentation of equipment losses, based on published imagery. Weaker provenance than physical documentation but far broader coverage, and useful for establishing what is present when nobody has inspected it.
EUR-Lex prerequisite The EU legal instruments, including the Council Decisions that fund iTrace and the common position governing member state arms exports. Read the funding decisions to understand the programme's scope and phase structure.

Legal, ethical and operational constraints

Reading and citing CAR's published reports is straightforward. The constraints arise from the content rather than the access. Serial numbers, precise recovery locations and any detail that could identify the individuals or units who cooperated with documentation carry real physical risk for those people and can end CAR's access to a theatre; treat them as sensitive regardless of the fact that they appeared in a public PDF. Where material relates to identifiable individuals, data protection law in most jurisdictions will apply to your retention of it notwithstanding its public origin. Findings about companies whose components appeared in weapons systems are defamation-sensitive if characterised as knowing participation rather than as a supply chain control failure, and the difference is not rhetorical – it is the difference between a defensible report and a claim you cannot support. If your work may feed enforcement or sanctions action, involve legal counsel early on the evidentiary standard that applies, because the standard for a designation, for a criminal prosecution and for a published assessment are three different things. Finally, do not use this material to construct anything resembling procurement guidance; the entire point of the source is enforcement and the analysis should be written so that its only usable conclusions are enforcement conclusions.

Operational security

Collection from the public website is a normal web request and reveals little. Approaching CAR for access identifies you and your institution to an organisation that maintains relationships with governments, which is fine for most institutional users and worth thinking about for anyone whose interest is sensitive. The larger consideration is downstream: if your analysis names intermediaries, brokers or facilitation networks, those entities have every incentive to identify who is investigating them, and the arms trafficking environment includes actors with the means to act on that. Keep case identifiers out of external queries, compartmentalise work on active networks, and be deliberate about who sees a draft that names a living person. Where your work touches a theatre in which CAR is deployed, be aware that careless publication can compromise their access and therefore the future of the collection you depend on – a coordination call before publishing is normal professional practice in this field, not a courtesy.

Two rules that hold regardless of jurisdiction. Collection that is lawful is not automatically proportionate, and a dataset assembled for one purpose does not carry consent for another. Where the records concern identifiable people, the question is not only whether you may hold the data but whether holding it serves the purpose you are accountable for.

Is it earning its place?

Sources accumulate. Feeds get added during an incident and are never reviewed again, and a decade later the pipeline is carrying dead weight that nobody dares remove. These are the measures that show whether Conflict Armament Research iTrace is contributing anything, and they are worth baselining now so the answer is available later.

  • Number of documented items in your local table with a complete marking record, tracked against the number where markings were absent or partial – the ratio characterises the tractability of the theatre.
  • Share of items where a transfer chain extends beyond first export, which measures how much accountability evidence you actually hold rather than how many items you have catalogued.
  • Diversion time-lag distribution by theatre and materiel class, watched for shifts that indicate a change from stockpile leakage to contemporary supply.
  • Count of intermediaries appearing in more than one report, which identifies the repeated nodes that individual documents make invisible.
  • Proportion of your assessments that state the sampling frame explicitly, treated as a mandatory quality gate rather than an aspiration.
  • Time from CAR publication to entity extraction and graph update in the platform, which measures whether a low-volume high-value source is actually being worked.
  • Rate at which findings you carried forward are later superseded or completed by subsequent CAR reporting, which tells you how stale your working picture runs.

Beware of volume. Indicator counts rise easily and say almost nothing. Unique contribution — findings this source produced that no other source in your stack would have — is the measure that matters, and it is usually far lower than anyone expects.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • Country of manufacture is not country of responsibility, and the gap between them is where all the analytical work lives – materiel is usually diverted well downstream of a producer who complied with every requirement.
  • The diversion time lag is the most informative derived variable in this domain and nobody publishes it as a field; compute it yourself from manufacture year and documentation date and it will separate stockpile leakage from live supply immediately.
  • An unanswered trace and an unattempted trace look the same in a summary and mean completely different things; read the report text, because CAR distinguishes them and secondary citation usually does not.
  • Ammunition headstamps are a strong identifier and a weak proof – codes have been reused, transferred and imitated, and factory code references are incomplete, so a headstamp identification should be stated as such.
  • The recovering party determines what enters the record, so a dataset built from materiel captured by one side is a dataset about the other side's supply, and using it to characterise the region is a category error.
  • For dual-use components, establish distribution breadth before attributing anything; a part available from thousands of resellers indicates a control gap in an ecosystem, not a decision by a manufacturer.
  • Craft production is growing and is invisible to marking-based tracing, so a declining share of traceable materiel in a theatre may reflect a shift in how weapons are made rather than an improvement in control.
  • Photographs of markings are the evidence and the database entry is an index; when a finding matters, look at the image, because transcription errors in marking data are real and consequential.
  • CAR's ability to work depends on relationships with the authorities who grant access, which means the published record is shaped by diplomacy as well as by evidence – and understanding that improves your reading rather than undermining it.

Questions analysts actually ask

Can I query the iTrace database directly?

Not as an open resource. The full database is intended for governments, international organisations and accountability mechanisms, and access arrangements have changed across programme phases. Most analysts should plan on the published report corpus, which is substantial and contains the underlying marking and trace evidence.

If a weapon was made in country X, does that mean X armed the group?

Almost never, and this is the single most common misreading. Materiel is typically diverted several transfers downstream of the manufacturer, often from a poorly secured stockpile in a third state. The accountable party is whoever lost custody, and establishing that is the entire purpose of the trace.

How current is the data?

Not very, by design. Documentation follows recovery, trace responses follow documentation, and publication follows both – so a report describes a period rather than a present state. Use it for provenance and pattern, and use other sources for what is in circulation today.

Why do some traces have no answer?

Because responding is a state's choice, and states decline for reasons ranging from record-keeping failure to unwillingness to disclose an embarrassing transfer. CAR reports non-response as non-response, which is itself informative – a pattern of silence from one state across many traces is a finding.

Is this admissible as evidence?

It is investigative documentation, not a seizure exhibit, and chain of custody for the physical item sits with the authority that recovered it. It has been used by UN panels and cited in accountability processes, but any specific evidentiary use is a question for the legal framework you are operating in and should be raised with counsel early.

Can I use published serial numbers in my own report?

You can, and you usually should not. Serial numbers and precise locations can identify the units and individuals who enabled the documentation, and republication transfers risk to them. Cite the finding and reference the report rather than reproducing the identifiers.

How does this differ from SIPRI's arms transfer data?

SIPRI models the authorised trade from open reporting and expresses volumes in its own trend-indicator units; CAR documents individual physical objects recovered from conflicts and traces them. One describes the legal market in aggregate, the other establishes specific illicit outcomes. They answer different questions and the tension between them is often the story.

What do component-level findings on commercial electronics actually prove?

That a controlled or uncontrolled part reached a weapons programme through some route. Whether that implicates the manufacturer depends entirely on how narrowly the part is distributed and what the manufacturer knew, and reports are careful about this even when coverage of them is not.

How stable is the programme?

It runs on funding renewed in phases, principally from the European Union, so continuity is a periodic political decision rather than a permanent arrangement. Build your dependency on it accordingly and mirror the published corpus locally rather than assuming it will always be retrievable.

Standards, formats and interoperability

What this source speaks natively, and what it has to be translated into before a partner can consume it. Work that arrives in a recognised format is easier to defend, easier to hand over and easier to automate against:

  • The International Tracing Instrument, which sets the marking and record-keeping expectations that make tracing possible at all and whose gaps explain most untraceable materiel.
  • The Arms Trade Treaty, particularly its diversion prevention provisions, which define what a diversion finding means in legal terms.
  • The UN Programme of Action on small arms and its associated implementation guidance, the policy framework within which national marking and stockpile management obligations sit.
  • Ammunition headstamp conventions and factory code references, which are the working vocabulary of ammunition identification and are incompletely documented in the open literature.
  • National and regional firearms marking requirements, including proof marking regimes, which determine what a given item should carry and therefore what its absence means.
  • UN Panel of Experts evidentiary practice, which uses the same marking-based method and is the closest thing to a shared standard for conflict materiel documentation.
  • Export control lists, including national munitions lists and dual-use schedules, which determine whether a documented component was controlled at the point it moved.
  • STIX 2.1 identity and relationship objects for expressing the supply-chain graph on export, with the honest caveat that STIX has no native concept of a physical item and the mapping is lossy.

References

Primary documentation and authoritative references for this source. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. Conflict Armament Research — Conflict Armament Research. The organisation and its full publication library. Start with a recent thematic report to see the method in operation before reading anything about it.
  2. iTrace — Conflict Armament Research. The programme page describing the global weapon reporting mechanism, its scope and its access model.
  3. Small Arms Survey — Small Arms Survey. The standing research reference on small arms, stockpile security, craft production and marking practice – the conceptual grounding for reading iTrace findings.
  4. SIPRI Arms Transfers Database — SIPRI. The authoritative model of the legal arms trade. Read the methodology page carefully; its trend-indicator values are not monetary and are widely misquoted.
  5. Arms Trade Treaty — ATT Secretariat. Treaty text, state reporting and the diversion prevention framework that makes a documented diversion legally consequential.
  6. UN Register of Conventional Arms — UNODA. State-declared transfers in the major conventional categories. Voluntary and incomplete, but a state's own declaration is a strong anchor when it exists.
  7. INTERPOL — INTERPOL. International policing cooperation including the firearms tracing mechanisms through which law enforcement trace requests actually move.
  8. UNODA — United Nations. The conventional arms policy framework, including the Programme of Action and the international tracing instrument.
  9. EUR-Lex — European Union. The Council Decisions funding iTrace and the EU common position on arms exports – read these to understand the programme's scope, phases and political basis.
  10. ACLED — ACLED. Georeferenced conflict event data for placing materiel documentation in operational context.

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this source: it ingests CAR's report corpus as dated evidence, resolves manufacturers, brokers and armed groups to platform entities, derives the diversion window for each documented item, and renders repeated intermediaries across separate investigations as a single supply-chain graph.. Browse the full source catalogue, or follow any tag above into the rest of the library.

Leave a Reply