Short answer
Supplier data becomes compliance evidence only after the company defines the request, verifies that the response covers the correct part and revision, assesses quality, and links it to a product requirement. Email attachments without status, ownership, and reassessment create false confidence.
Key takeaways
- The data profile should vary by material, product, and legal act.
- Separate received, validated, approved, rejected, and expired.
- Data gaps need deadlines, escalation, and business decisions.
- Supplier or part changes must trigger renewed review.
This content is a practical overview, not legal advice. Always verify the current legislation and the requirements that apply to your product. Research uses official primary sources; competitor content is used only to identify questions and content gaps.
Start with a data requirement profile
Define required declarations, test reports, certificates, standards, and identity fields for each purchased item. Specify scope, threshold, language, validity, and format. A generic questionnaire sent to every supplier often creates volume rather than decision quality.
Collect against the correct part and legal entity
Request supplier part number, internal cross-reference, revision, manufacturing site, and the legal entity making the statement. A family-level response must not automatically cover every variant. Retain the original file and communication.
Layered validation
Check completeness and identity, then technical plausibility, and finally whether evidence covers the legal requirement. An authentic document may be irrelevant, stale, or for the wrong model. Give each deviation a code, comment, and owner.
Escalate gaps as business risk
Set response time, reminders, and escalation level. Without data, the business chooses an alternative supplier, targeted testing, redesign, market restriction, or documented risk acceptance. Compliance should not carry sourcing risk alone.
Measure quality, not only response rate
Useful metrics include coverage of critical items, validated-response share, average age, open high-risk gaps, and closure time. A 95% response rate can mislead if the missing 5% contains the most critical materials.
Ownership and reassessment
Assign owners for requirements, supplier contact, technical review, and final approval. Triggers include a new law, substance list, standard, supplier, site, material, or part revision. Escalation rules should state when no response blocks release and when alternative evidence or testing is acceptable.
How Verca can support the process
Verca can structure supplier requests, documents, item links, status, and revision history. Approval and testing strategy remain with the responsible organisation.
Frequently asked questions
Is a supplier CE certificate sufficient?
No. Verify document type, issuer, product identity, legal act, and whether it supports assessment of the finished product.
How often should data be renewed?
After defined validity and relevant change. High-risk evidence should be reviewed more frequently than stable low-risk data.
Who should approve a supplier response?
A designated competent function with access to product requirements; procurement may collect but should not alone give technical or legal approval.
What if a supplier does not respond?
Escalate and make a documented risk and sourcing decision. Unknown status is not approved status.
Official sources
Primary sources used for this guide.