Product Compliance Audit: What Growing Brands Should Review Before Retail or Marketplace Expansion

Most businesses do not decide to audit product compliance because everything is calm.
Usually something has changed.
A retailer has asked for documents. Amazon has requested evidence. A new distributor wants a compliance pack. The business is entering the EU. An investor has started due diligence. Or the product range has simply grown to the point where nobody is completely sure which files are current.
That is when a compliance audit becomes useful.
Not because an audit produces another certificate to put in a folder, but because it tells management what is actually controlled, what is missing and what could block the next commercial step.
For a growing brand, that visibility can be more valuable than commissioning another isolated test report.
Who Does This Apply To?
Brands Preparing for Retail: Major retailers often ask more detailed questions than a DTC business has previously faced.
Marketplace Sellers: Amazon and other platforms can request test reports, declarations, traceability information or product-safety evidence with little warning.
Importers and Distributors: A growing supplier portfolio can leave documentation scattered across emails and shared drives.
Businesses Entering New Markets: UK, EU and US expansion can expose assumptions that were never tested against the destination market.
Multi-Category Brands: A company selling cosmetics, supplements and general consumer products cannot use one compliance checklist for everything.
Businesses Considering Outsourced Support: An audit is often the cleanest way to establish the baseline before deciding what ongoing support is actually needed.
What Does a Product Compliance Audit Mean in Practice?
Start With the Product Register
Before opening technical files, establish what the business actually sells.
That means active SKUs, variants, models, brands, suppliers, manufacturing locations and markets.
It sounds obvious. In practice, we often find the commercial product list and the compliance product list are not the same thing.
If the business cannot say which version is live, it cannot reliably say which document belongs to it.
Check Classification and Applicable Rules
Every product needs the right regulatory route.
Is it a cosmetic? Food supplement? Electrical product? Toy? General consumer product? Does CE marking apply? Does GPSR apply? Are there chemical, battery, packaging or other requirements sitting alongside the headline regime?
A beautifully organised file built around the wrong classification is still the wrong file.
Test the Supplier Evidence
A folder containing twenty PDFs is not automatically a technical file.
Check whether the test report names the actual model being sold, whether the standard is relevant, whether the certificate is current, whether the manufacturer matches the supply chain and whether the specification agrees with the finished product.
This is one of the biggest differences between collecting documents and reviewing them.
Review Labels and Online Claims
Compliance information can drift after launch.
The technical team approves one warning. Marketing changes the packaging six months later. A marketplace description uses a stronger claim. The supplier changes an ingredient name but nobody updates the artwork.
An audit should compare the product file against the actual labels and packaging and, where relevant, the live e-commerce listings.
Check Economic-Operator and Market Responsibilities
Who is the manufacturer? Who imports the product? Who is named on the label? Is an Authorised Representative, Responsible Person, FBO or other economic operator required?
The answer can change by product category and market.
This should be mapped rather than inferred from whoever happens to have a local address.
Look at Post-Market Controls
A launch file is only half the story.
The audit should ask how complaints are logged, how safety incidents are escalated, how batches or serial numbers are traced, who can stop sales, and what would happen if a recall became necessary.
OPSS guidance makes clear that businesses have responsibilities when products are unsafe or non-compliant. A good system needs to work before the first serious issue arrives.
Check Change Control
This is the area that tells you whether the compliance system can scale.
If a factory changes a component, fragrance, raw material, firmware version, battery or packaging supplier, who decides whether testing, the risk assessment, declaration, PIF, label or listing needs updating?
If the answer is “the supplier usually tells us if it matters”, the business does not really have change control.
Common Mistakes Businesses Make
1. Auditing the Folder Instead of the Product
The objective is not to count PDFs. It is to decide whether the evidence supports the product currently being sold.
2. Treating Supplier Certificates as Self-Explanatory
Model numbers, dates, standards, configurations and issuing bodies need to be checked. A certificate that looks impressive can still be irrelevant.
3. Ignoring Website and Marketplace Copy
Claims and warnings used online can create compliance issues even when the physical label is better controlled.
4. Reviewing Only New Products
The oldest best-seller can be the highest-risk product in the portfolio because nobody has revisited its file for five years.
5. Producing a Huge Gap List With No Priorities
A useful audit separates urgent safety or market-access issues from housekeeping. Management needs to know what to fix first.
6. Fixing the Backlog Without Fixing the Process
If the same supplier can send the next product with the same missing evidence, the audit has treated the symptom, not the cause.
Your Product Compliance Audit Checklist
Portfolio: Do you have a controlled list of every active SKU and variant?
Classification: Has each product been mapped to the correct regulatory regime?
Markets: Is it clear where each product is legally offered for sale?
Economic Operators: Are manufacturer, importer, RP, AR, FBO or other roles correctly assigned?
Risk Assessments: Are product risks documented where required and do they match foreseeable use?
Testing: Do reports apply to the actual model, materials and configuration being sold?
Declarations: Are Declarations of Conformity current and correctly signed where applicable?
Technical Files: Can the core evidence be located quickly?
Labels: Do current production labels match the approved compliance position?
Claims: Are product, health, cosmetic or performance claims supportable?
Online Listings: Do live listings contain required operator and safety information?
Traceability: Can affected batches, serials, suppliers and customers be identified?
Complaints: Is there a defined route for escalating safety concerns?
Recall: Does the business know who can make and execute a withdrawal or recall decision?
Change Control: Are supplier and product changes assessed before they reach the market?
How Conformity Services Can Help
We use compliance audits as a practical starting point for businesses that need visibility before deciding what to fix, outsource or build internally.
Our outsourced compliance support can begin with a defined portfolio review covering:
- product and market mapping;
- technical-file and risk-assessment gaps;
- supplier evidence and testing;
- labels, packaging and claims;
- economic-operator responsibilities;
- marketplace and e-commerce readiness;
- complaint, incident and recall processes;
- change control and document ownership; and
- a prioritised corrective-action plan.
Where the audit finds a historic backlog, we can scope that as a project. Where it shows a recurring operational need, we can then discuss whether ongoing support makes sense.
That is the same principle we set out in our guide to project-based vs ongoing compliance support: fit the support model to the workload, not the other way around.
Final Thoughts
A compliance audit should make the business easier to run.
You should come out knowing what you sell, which rules apply, where the evidence is, who owns each responsibility and what needs fixing first.
If all you receive is a longer folder and a hundred-item spreadsheet with no priorities, the exercise has missed the commercial point.
Growing brands do not need perfect paperwork for the sake of paperwork.
They need a compliance system that can stand up when a retailer, regulator, marketplace or new market asks a real question.
Sources and official guidance
This article provides general information, not legal advice. Audit scope should be tailored to the product categories, markets and economic-operator roles involved.
- OPSS: Product safety advice for businesses
- OPSS: Business notifications of unsafe and non-compliant products
Need a Clear View of Your Compliance Position?
Conformity Services can review a representative product range or wider portfolio and turn the gaps into a prioritised action plan.
That gives you a baseline before retailer onboarding, marketplace expansion or a move into a new market.
Find the gaps internally before somebody else finds them for you.