Latest News

Latest News

Compliance Evidence Collection: What to Collect and What to Do When Data Is Missing

Compliance Evidence Collection: What to Collect and What to Do When Data Is Missing

Compliance Evidence Collection: What to Collect and What to Do When Data Is Missing

Hariprasanth

Hariprasanth

Hariprasanth

Hariprasanth

Calendar

Compliance Evidence Collection: What to Collect and What to Do When Data Is Missing
Compliance Evidence Collection: What to Collect and What to Do When Data Is Missing

Compliance evidence collection is the process of gathering and retaining the documentation that proves a product, material, or supplier meets a specific regulatory or customer requirement. For global manufacturers, the hard part is rarely knowing which rules apply. The hard part is assembling verifiable proof across thousands of parts and multiple supplier tiers, and knowing what to do when some of that proof never arrives.

This guide explains what compliance evidence you need to collect by framework, how requirements change across audit types, and the defensible steps to take when supplier data is incomplete. If you want to understand where your current evidence gaps sit, you can book a compliance risk assessment to map exposure across products and jurisdictions.

What Counts as Compliance Evidence?

Compliance evidence is any record that substantiates a compliance claim. A statement that a product is "RoHS compliant" carries no weight without the underlying proof. That proof is the evidence.

Most manufacturers rely on a recurring set of evidence types:

  • Supplier declarations (declarations of conformity, material compliance statements)

  • Full material declarations (FMD) and substance-level disclosures

  • Test reports (laboratory analysis, XRF screening)

  • Certificates of conformance (CoC)

  • Mill test reports (MTR) for metals and alloys

  • Safety data sheets (SDS)

  • Smelter and country-of-origin data for minerals

Two document types deserve particular attention because they appear across nearly every framework. The certificate of conformance confirms a product meets stated specifications, while the mill test report documents the chemical and mechanical properties of a material batch.

Which Evidence Each Framework Requires

Evidence requirements differ by regulation. Collecting the wrong document, or a declaration that does not reference the correct threshold, leaves a gap that surfaces during an audit. The table below maps common frameworks to the evidence that typically supports them.

Framework

Core Evidence Required

Key Threshold / Scope

REACH (SVHC)

Supplier declarations, SCIP notification references, FMD

0.1% w/w in articles

RoHS

Declaration of conformity, test reports, technical file

0.1% w/w (0.01% cadmium)

PFAS (TSCA 8(a)(7))

Manufacture/import records, supplier PFAS statements

Any reportable PFAS presence

California Prop 65

Supplier statements, exposure assessments, warnings

Listed-substance exposure

Conflict Minerals

CMRT, smelter identification, country-of-origin inquiry

3TG (tin, tungsten, tantalum, gold)

Under REACH, suppliers must communicate the presence of Substances of Very High Concern above 0.1% by weight in articles, and producers of articles must notify the SCIP database maintained by ECHA. You can review the obligation detail on Certivo's REACH framework page and the RoHS framework page.

For PFAS, reporting obligations under TSCA Section 8(a)(7) require manufacturers and importers to report PFAS they have made or imported, and timelines have shifted during rulemaking. Confirm the current reporting window directly with the US EPA before relying on an internal date. Certivo's view of evidence capture for PFAS compliance reflects how quickly these requirements move.

Compliance evidence collection requirements by framework for global manufacturers

Click on image to view full

Evidence Requirements Change by Audit Type

The same product can face four different evidence standards depending on who is asking. Treating all audits as identical is a common source of last-minute scrambling.

Audit Type

Who Drives It

What Evidence Is Expected

Internal audit

Compliance / quality team

Current declarations, test records, gap log

Customer audit

OEM or brand customer

Product-level proof, RFQ responses, FMD

Regulatory inspection

ECHA, EPA, CPSC, market surveillance

Due diligence records, notifications, dated declarations

Certification audit

ISO 9001, IATF 16949, ISO 14001

Process evidence, controlled documents, traceability

Customer audits increasingly demand product-level and BOM-level proof rather than a single company statement, which is why responding faster to customer RFQs depends on how your evidence is organized. Regulatory inspections focus heavily on documented due diligence, not only on whether data is complete. Staying audit-ready across frameworks means your evidence can answer each of these four standards on demand.

Why You Will Never Have 100% of the Data

No enterprise manufacturer holds complete evidence for every part. The gaps are structural, not a sign of a failing program. They arise from predictable causes:

๐Ÿ”— Deep multi-tier supply chains where sub-tier suppliers are not visible

โš ๏ธ Suppliers who do not respond, respond late, or submit incomplete declarations

โš ๏ธ Obsolete or long-lifecycle parts with no active supplier contact

โš ๏ธ Confidential formulations withheld as intellectual property

๐Ÿ“„ Legacy data inherited through acquisitions or ERP migrations

The question is not how to reach perfect coverage. The question is how to build a defensible position with the evidence you can collect, and how to document the effort behind the gaps you cannot close. This is where streamlining supplier documentation moves from a convenience to a risk control.

What to Do When You Do Not Have All the Compliance Evidence

Missing data does not automatically mean non-compliance. Most frameworks are built around reasonable, documented due diligence rather than omniscience. The practical response is a structured sequence, not a single fix.

1. Document your due diligence

A good-faith, recorded effort to obtain evidence is itself evidence. For conflict minerals, the expectation is a reasonable country-of-origin inquiry conducted in line with the OECD Due Diligence Guidance. Keep dated records of requests sent, reminders issued, and responses received. Certivo's conflict minerals framework treats this inquiry trail as a first-class record.

2. Prioritize by risk, not by volume

Direct your limited time toward high-risk substances, high-volume parts, and products sold into the strictest jurisdictions. A part with no restricted-substance exposure does not warrant the same urgency as a component likely to contain an SVHC. Managing compliance risk proactively depends on scoring exposure before chasing documents.

3. Use alternative and secondary evidence

Where a direct supplier declaration is missing, defensible substitutes may include analogous-part data, material-level inference from a known specification, or independent laboratory testing. Lab testing is often the fallback when a supplier cannot or will not disclose. Record the basis for any inferred conclusion so an auditor can follow the logic.

4. Escalate supplier follow-ups systematically

Manual email chasing does not scale across thousands of suppliers. Automated, tracked follow-ups with clear deadlines close more gaps and leave a verifiable trail of attempts. Moving suppliers onto a self-service portal reduces the back-and-forth that buries data requests in inboxes.

5. Log every gap transparently

A visible, maintained gap register is a sign of control, not weakness. It shows auditors exactly what is known, what is pending, and what compensating evidence is in place. Hiding gaps is far riskier than documenting them.

Decision workflow for handling missing compliance evidence and supplier data gaps

Click on image to view full

Building a Defensible Evidence Trail

Audit readiness is fundamentally a data and evidence problem, not a document-storage problem. When a customer or regulator asks what a product contained at the point of sale, you need a point-in-time answer, not today's best guess.

A defensible trail depends on:

  • Time-stamped declarations tied to specific product and BOM versions

  • Historic state tracking, so you can reconstruct compliance as it stood on any date

  • Clear evidence provenance: who provided it, when, and under what authority

  • Immutable logs that record changes rather than overwriting them

Spreadsheets cannot reliably hold this history at enterprise scale, which is why many teams are replacing spreadsheets with a scalable system and anchoring evidence to the bill of materials through BOM-level compliance tracking.

How AI Reduces Evidence Gaps

Most evidence problems are volume problems. Thousands of certificates, test reports, and declarations arrive in inconsistent formats, and manual review cannot keep pace. AI-native compliance automation addresses the collection, extraction, and validation burden directly.

Certivo uses CORA-powered regulatory intelligence to parse incoming documents, extract substance and threshold data, and validate it against the correct regulatory limits. This matters in three places:

  • Document parsing: CORA reads certificates, mill test reports, and SDS files and structures the data automatically, reducing manual entry

  • Certificate validation: incoming declarations are checked against the applicable threshold, flagging statements that do not actually support the claim

  • Gap identification: the platform shows which parts lack valid evidence and prioritizes follow-up by risk

Because this runs continuously, the shift is from reactive, pre-audit scrambles toward continuous, audit-ready documentation. Certivo also removes the need for suppliers to submit data in a rigid format, as described in why you do not need IPC-1752 submissions, and automates collection at scale for article importers handling PFAS supplier data. For the broader picture, see AI tools for compliance management.

Compliance Evidence Collection Checklist

โœ… Map each product and BOM to its applicable frameworks and required evidence types

โœ… Define the acceptable evidence standard for each framework and audit type

โœ… Score parts and suppliers by risk to prioritize collection effort

โœ… Automate supplier requests and escalations with dated tracking

โœ… Validate every declaration against the correct threshold, not just its presence

โœ… Maintain a transparent, current gap register with compensating evidence noted

โœ… Preserve time-stamped, point-in-time records for historic audit queries

โœ… Review regulatory changes so new obligations trigger new evidence needs

Before a customer or regulator asks, you can request a compliance review to confirm your evidence trail holds up across frameworks and supplier tiers.

FAQs

FAQs

What compliance evidence do manufacturers need to collect?

Manufacturers typically collect supplier declarations, full material declarations, test reports, certificates of conformance, mill test reports, safety data sheets, and country-of-origin data. The exact set depends on the applicable frameworks such as REACH, RoHS, PFAS, and conflict minerals. Certivo maps required evidence to each product and BOM.

What should I do if I do not have all the supplier compliance data?

Document your due diligence, prioritize high-risk parts, use alternative evidence such as lab testing or analogous-part data, and maintain a transparent gap register. Most frameworks expect reasonable, documented effort rather than perfect data. CORA helps identify and prioritize gaps automatically.

Is a good-faith effort to collect evidence legally sufficient?

Many frameworks, including conflict minerals due diligence, are built on a reasonable inquiry standard rather than complete certainty. Dated records of requests, reminders, and responses form part of your evidence. Always confirm the specific standard with the relevant authority such as ECHA or EPA.

How is audit evidence different for customer audits versus regulatory inspections?

Customer audits usually require product-level and BOM-level proof tied to specific RFQs, while regulatory inspections focus on documented due diligence, notifications, and dated declarations. Certivo keeps point-in-time records so both standards can be answered from one system.

How can automation help validate supplier certificates at scale?

AI document parsing extracts substance and threshold data from certificates, mill test reports, and SDS files, then validates each against the correct regulatory limit. This flags declarations that do not support the claim and highlights missing evidence, reducing manual review and audit surprises.

What compliance evidence do manufacturers need to collect?

Manufacturers typically collect supplier declarations, full material declarations, test reports, certificates of conformance, mill test reports, safety data sheets, and country-of-origin data. The exact set depends on the applicable frameworks such as REACH, RoHS, PFAS, and conflict minerals. Certivo maps required evidence to each product and BOM.

What should I do if I do not have all the supplier compliance data?

Document your due diligence, prioritize high-risk parts, use alternative evidence such as lab testing or analogous-part data, and maintain a transparent gap register. Most frameworks expect reasonable, documented effort rather than perfect data. CORA helps identify and prioritize gaps automatically.

Is a good-faith effort to collect evidence legally sufficient?

Many frameworks, including conflict minerals due diligence, are built on a reasonable inquiry standard rather than complete certainty. Dated records of requests, reminders, and responses form part of your evidence. Always confirm the specific standard with the relevant authority such as ECHA or EPA.

How is audit evidence different for customer audits versus regulatory inspections?

Customer audits usually require product-level and BOM-level proof tied to specific RFQs, while regulatory inspections focus on documented due diligence, notifications, and dated declarations. Certivo keeps point-in-time records so both standards can be answered from one system.

How can automation help validate supplier certificates at scale?

AI document parsing extracts substance and threshold data from certificates, mill test reports, and SDS files, then validates each against the correct regulatory limit. This flags declarations that do not support the claim and highlights missing evidence, reducing manual review and audit surprises.

Table of Contents
No headings found on page
Table of Contents
No headings found on page

See how Certivo can automate compliance for your business.

See how Certivo can automate compliance for your business.

See how Certivo can automate compliance for your business.

Book a demo

Book a demo

Hariprasanth

Hariprasanth is a Chemical Compliance Specialist with nearly four years of experience, underpinned by a degree in Chemical Engineering. He brings in-depth expertise in global product compliance, working across key regulations such as REACH, RoHS, TSCA, Proposition 65, POPs, FMD, and PFCMRT.

Hariprasanth specializes in reviewing technical documentation, validating supplier inputs, and ensuring that products consistently meet regulatory standards. He works closely with cross-functional teams and suppliers to collect accurate material data and deliver clear, audit-ready compliance reports that stand up to scrutiny.

Through his strong analytical skills and regulatory insight, Hariprasanth enables organizations to navigate evolving compliance challenges while aligning with sustainability initiatives in an increasingly dynamic regulatory environment.