The Compliance Document Everyone Assumed Someone Else Had

Somewhere in a shared drive is a BSCI certificate, a REACH declaration, or a test report that everyone on the sourcing and compliance team believes covers the current order. Nobody checked it this quarter. Nobody checked which production site it applies to. And when a retailer compliance audit or a customs query comes in, the document that was supposed to be the answer turns out to be the wrong version, the wrong site, or simply expired.
This isn't a knowledge failure. Everyone involved knew the certification requirement existed. It's an ownership failure — the assumption that because the document exists somewhere, someone has verified it applies to this order, this factory floor, this shipment.
Compliance Failures Aren't Knowledge Gaps — They're Ownership Gaps
Supply chain fragmentation makes this worse by design, not by accident. Nearly half of fashion brands — 45% by one industry estimate — report struggling to verify sustainability and compliance claims from their own suppliers. That's not because the claims are absent. It's because verifying them requires an active check that fragmented, multi-tier supply chains make easy to skip.
Three Places the Assumption Breaks Down
1. Site-specific certification. A BSCI or SMETA audit certificate is issued for a specific production facility, not for a company name. A factory group operating two or three production sites under one legal entity can hold a valid, current audit for Site A while Site B — the one your order is actually running through — has never been inspected. Buyers who file "the factory's BSCI certificate" without confirming the facility code often discover this gap only when a retailer's own compliance team cross-checks the audit database and finds a mismatch.
2. Currency and expiry. BSCI audits are typically valid for two years, with a required follow-up at the one-year mark for facilities that scored lower on their initial assessment. A certificate collected at onboarding two and a half years ago isn't current — it's expired, and nobody flagged it because compliance documentation review usually happens once, at supplier approval, not on a recurring cadence.
3. Product and substance applicability. REACH compliance illustrates this well. Under REACH, a supplier must provide a safety data sheet when placing on the market a substance or mixture that's classified as hazardous, is persistent/bio-accumulative/toxic, or appears on the Candidate List. A generic compliance letter referencing "REACH compliant materials" without naming the specific Candidate List version or the specific substances tested doesn't actually establish compliance for a new hardware finish or coating introduced mid-season.
Who Actually Owns Compliance Responsibility — And Why It Doesn't Transfer Automatically
This is the part buyers most often get wrong: a supplier's compliance activity in their home country does not discharge the buyer's own regulatory obligation. Under REACH, the EU importer — the legal entity bringing goods into the EU market — bears direct regulatory responsibility, regardless of what the factory has done on its end. The importer is required to set specific requirements for suppliers, particularly for high-risk materials, and to confirm the supplier holds all necessary documentation before the product reaches market — and to retain that documentation for a minimum of ten years under REACH Article 36.
In practice, this means a buyer cannot treat "the factory says it's compliant" as the end of the verification chain. The factory's declaration is an input. The buyer's own documented verification is the actual compliance position — and it's the buyer's name on the liability if a market surveillance authority asks for records five years from now.
A Compliance Document Audit Framework for Buyers
Checklist — before assuming a compliance document is valid:
Does the certificate name the exact production site (facility code, not just company name) that will run this order?
Is the certificate within its current validity window, including any required interim follow-up?
Does the declaration reference the current version of the applicable regulatory list (e.g., REACH Candidate List date), not a generic statement?
Is the document specific to the materials, hardware, or coatings actually used in this product, or is it a blanket claim covering unrelated SKUs?
Who on your team is responsible for re-verifying this on a recurring schedule — and is that ownership written down anywhere?
Building Compliance Ownership Into Supplier Management, Not Just Onboarding
Compliance documentation collected once at onboarding has a shelf life. The buyers who avoid the "assumed someone else had it" failure treat compliance verification as a recurring operational task — tied to certificate renewal dates, new material introductions, and periodic re-confirmation of site-specific scope — rather than a one-time gate that gets checked off and forgotten.
That requires a named owner internally. Not "compliance team" as an abstract department, but a specific person who reviews certificate status against a tracked expiry calendar, cross-checks new materials or hardware against existing declarations, and flags gaps before a retailer or customs authority does.
Next step: If your team needs a current compliance document pack — certification status, site-specific audit scope, and material declarations — for an upcoming retailer or customs review, contact our specialist for detail on how we can help you verify them.




