Buyer questionAnswered from the China side

Supplier approval: certificates describe a facility. Contracts bind an entity.

An approved supplier program is a documented process for deciding which suppliers may be used, on what evidence, and how often that evidence is refreshed. In regulated sectors — food most visibly, but also medical devices, cosmetics and children’s products — it is an auditable requirement rather than good practice. Almost every input to it is a document the supplier provides: certificates, test reports, questionnaires, audit summaries. Each of those names a legal entity, and the approval file is only as sound as the answer to one question nobody in the certificate chain checks — is that entity the one you are contracting with and paying?

· 6-minute read · Prepared by Currawong’s China-side desk.

SUPPLIER APPROVAL / 01

Approval files fail at the join, not at the standard.

This page covers one link in the chain: the identity of the entity behind the paperwork. It is not a guide to any certification scheme, and we are not an auditor.

01

What an approved supplier program contains

Programs differ by sector and by scheme, but the structure is consistent: criteria for approval, the evidence required to meet them, a decision record, a periodic review, and a defined path for removing a supplier. Typical evidence includes the applicable certification, product test reports, a completed supplier questionnaire, and increasingly a second-tier disclosure — who supplies your supplier.

Where the goods are imported, the buyer normally carries the obligation. Importers into regulated markets are generally expected to verify their foreign suppliers rather than rely on the exporter’s own assurance — the specific requirement depends on your destination market and product, and your regulator or scheme owner is the authority on it, not a guide written elsewhere.

One structural point worth naming: this evidence set is almost entirely supplier-supplied. That is not a criticism of it — certification exists precisely so that a third party attests to something. But it means the file inherits whatever assumption was made about who the supplier is.

02

The step certificates do not cover

A certificate attests that a named organisation or site met a standard at an audit date. It is silent on everything that happens afterwards in your transaction, and in particular on three things that decide whether the approval means anything:

Whether the certified entity is your counterparty. It is common, and often entirely legitimate, for a factory to hold the certification while a separate trading company issues the invoice and receives payment. It is also exactly how a certificate belonging to someone else gets attached to an approval file. The two entities have different registered names and different identifiers, and comparing them takes minutes.

Whether the entity is currently in good standing. Certificates do not track the registration status of the holder. A company can be certified and, separately, be struck off, revoked or listed as abnormal.

Whether the entity is registered to do this at all. The registered scope of business states the activities the company is registered for — including whether it may manufacture, or only trade. Reading manufacturer versus trader from the registered scope.

03

What to check on the Chinese record at the approval stage

Each item resolves to a fact with a source and a query date:

Exact registered Chinese name and 18-character Unified Social Credit Code, taken from a photograph of the business licence (营业执照) and then checked against the register rather than against the photograph. How the check is run.

The same name and code appear on the certificate, the contract, the invoice and the payment instruction. Where they differ, the difference itself needs an explanation before approval — not after the first shipment.

Registration status is active, and the registered scope covers the activity being approved.

Public irregularity signals — abnormality listings, administrative penalties, former names. Penalties in the same domain as your approval criteria are the ones that matter most. What a certificate can and cannot be checked against.

The payment beneficiary matches the approved entity. How to compare the beneficiary against the register.

04

Keeping approval current

Approval files age in a specific way: the certificate has an expiry date printed on it, so it gets re-requested, while the entity facts have no expiry date and quietly go stale. Registered names change. Companies are restructured. A supplier approved two years ago under one entity may be invoicing today under another, and nothing in the certificate cycle would surface that.

A practical rule: re-check the entity facts on the same cadence as the certificate, and additionally whenever the invoicing name, the bank details or the contact company changes. Those three changes are the observable ones, and each is a reason to look before the next payment.

05

What we are not

Stated plainly, because this is a compliance context and vagueness would be worse than useless:

We are not a certification body or an accredited auditor. We do not issue, endorse or renew any certification, and nothing we produce belongs in an approval file as evidence of conformity.

We do not perform food-safety or scheme audits — HACCP, GFSI-benchmarked schemes, or any regulator’s programme. Those require accredited auditors on site.

We do not determine whether a supplier meets your regulatory obligations. That determination is yours, against requirements set by your destination market.

What we do is the identity and standing layer: retrieve the Chinese public record for a named entity, report it with source and retrieval date, and state what could not be read. An on-site visit is a separately arranged service, quoted per visit, and is a factory verification — not a scheme audit.

06

Starting with a supplier already in your file

If you hold a certificate and an invoice for the same supplier, the fastest useful check is whether both name the same registered entity, and whether that entity is currently active.

Run the free registry check

Not legal or regulatory advice. Records are reported with their source and retrieval date; a record check is not an approval decision and does not certify that a supplier is safe or compliant.