Skip to main content
EU Cosmetics Regulation 1223/2009

Supplier Qualification for EU Cosmetics Brands: The REACH Declarations, COAs, and Audit Records Your PIF Actually Needs

EU cosmetics brands often discover supplier documentation gaps during audits. Here's the REACH declarations, COAs, and audit records your PIF requires.

Nour Abochama Quality & Regulatory Advisor, Care Europe | VP Operations, Qalitex

Temel Çıkarım

EU cosmetics brands often discover supplier documentation gaps during audits. Here's the REACH declarations, COAs, and audit records your PIF requires.

Three out of every five Product Information Files our team reviews are missing at least one supplier document. Not because brand owners have been careless — they’ve usually collected COAs, completed their CPNP notification, and commissioned a Cosmetic Product Safety Report. What’s missing is typically something quieter: a REACH declaration that was never requested, a COA that hasn’t been re-issued since the supplier changed their analytical method, or an audit record that exists on someone’s hard drive but never made it into the PIF.

Under EU Cosmetics Regulation 1223/2009, your PIF must be maintained for 10 years from the date of the last batch placed on the market (Article 11). During a DGCCRF inspection or a complaint-driven audit, that file is your only defence. And the section that unravels first is almost always the supplier documentation.

Here’s what “adequate” actually looks like — and where the gaps tend to hide.

What ISO 22716 Actually Requires from Your Supplier Files

ISO 22716:2007 — the GMP standard for cosmetics and the reference standard under Regulation 1223/2009 — covers supplier management in Section 8 (Starting Materials) and Section 10 (Quality Control). The language is deliberately non-prescriptive, which is part of the problem. It says you should verify “the conformity of materials purchased,” but it doesn’t enumerate a minimum document set.

Regulators and safety assessors have filled that gap over years of enforcement. For each raw material, a robust supplier file should contain:

  • A current Certificate of Analysis — issued within the last 12 months, or per-batch for higher-risk materials
  • A Safety Data Sheet (SDS) conforming to the REACH SDS format under Regulation (EC) No 453/2010 (now Annex II of the REACH Regulation as updated)
  • A REACH compliance declaration confirming whether the material or its components appear on the SVHC Candidate List
  • Evidence of the supplier’s own GMP status — an ISO 22716 certificate, a third-party audit report, or a relevant regulatory authority inspection record
  • For botanical ingredients: an identity specification with supporting analytical data (TLC, HPTLC, or where appropriate, DNA confirmation)

None of this is optional if your Responsible Person intends to defend the safety assessment. The SCCS (Scientific Committee on Consumer Safety) states explicitly in its Notes of Guidance for the Testing of Cosmetic Ingredients and Their Safety Evaluation (11th revision) that ingredient identity and purity must be documented to an extent that supports the toxicological conclusions in the CPSR. A safety assessor who can’t verify what they’re assessing can’t sign.

REACH Compliance Declarations: What “Compliant” Actually Means

The phrase “REACH compliant” appears on thousands of supplier declarations across Europe. On its own, it means almost nothing.

REACH (Regulation EC No 1907/2006) imposes different obligations depending on where you sit in the supply chain. Manufacturers and importers above one tonne per year must register their substances with ECHA. Downstream users — which most cosmetic formulators are — primarily need to ensure they receive adequate Safety Data Sheets and are notified when a substance they use appears on the SVHC Candidate List.

The Candidate List currently contains over 240 substances of very high concern, including endocrine disruptors, carcinogens, and persistent, bioaccumulative, and toxic (PBT) substances. When a supplier tells you their material is “REACH compliant,” what you actually need confirmed is:

  1. Has the substance (or each relevant component in a mixture) been registered by the upstream manufacturer or importer with ECHA?
  2. Does the supplied concentration trigger an SDS obligation? The threshold under REACH is ≥1% w/w for hazardous substances in a mixture, dropping to ≥0.1% w/w for CMR category 1A or 1B substances.
  3. Does any component appear on the Candidate List, even below those thresholds? Under Article 33 of REACH, the supplier is obligated to inform you — but only if you ask, and only if the concentration exceeds 0.1% w/w in the article as supplied.

A one-line letter saying “we confirm our product is REACH compliant” answers none of these questions. What you want is a substance-specific declaration that cites ECHA registration numbers where applicable, confirms the Candidate List screening result, and — critically — states the date of that screening. The Candidate List is updated twice a year, typically in June and November. A declaration issued in early 2024 may not reflect substances added since then.

For ingredients that travel through several intermediaries before reaching you, a Chain of Custody (CoC) declaration tracing REACH compliance back to the original manufacturer adds meaningful assurance. These aren’t legally mandated under REACH, but they’re increasingly expected during supplier audits and are genuinely difficult to obtain after the fact.

The COA Red Flags That Invalidate Your Safety Assessment

A Certificate of Analysis is the most universally collected document in cosmetics supply chains — and one of the most consistently misread. Here are the specific red flags that a qualified safety assessor will flag and that can force a PIF revision if left unaddressed.

Identical batch data across multiple deliveries. If every COA for a botanical extract shows exactly the same values for moisture content, heavy metals, and microbial counts — to the same decimal places — that’s a fabrication signal, not consistency. Legitimate analytical data shows natural variation. A spread of 0.003–0.008% for lead across 12 batches is credible. Exactly 0.005% every time is not.

Results without cited methods. A COA that lists a heavy metals result without specifying the analytical method (ICP-MS, ICP-OES, AAS) and the reference standard applied (USP <232>, Ph.Eur. 2.4.27, or similar) gives you nothing to verify against. Your safety assessor can’t confirm the limits are appropriate if the methodology is unknown.

Internal lab results with no accreditation. ISO 22716 doesn’t require third-party testing for every batch. But where you’re relying on a supplier’s internal COA for a risk-relevant parameter — heavy metals in a botanical, microbial counts in an emulsifier, preservative efficacy in a finished blend — ISO/IEC 17025 accreditation on that test provides meaningful independent assurance. Without it, you’re accepting the word of a party with direct commercial interest in the result.

Specifications that predate a supplier change. If a supplier changes their manufacturing site, shifts from one geographic origin to another, or modifies their extraction process, a COA from the prior configuration is technically compliant with a specification that no longer reflects what you’re receiving. This matters acutely for botanicals, where origin strongly influences pesticide residue and heavy metal profiles.

When Independent Third-Party Testing Replaces the Supplier’s Word

Supplier documentation alone isn’t always sufficient, and there are circumstances where independent laboratory verification becomes functionally necessary rather than merely best practice.

If you’re a Responsible Person under Regulation 1223/2009, you carry personal legal accountability for product safety. If your safety assessor identifies a documentation gap — an unverified SVHC screen, an impurity profile for an excipient that’s never been characterised, a botanical ingredient with no confirmed identity — they can’t sign off on the CPSR. The PIF is incomplete. The product cannot legally be placed on the EU market.

Independent testing resolves this in at least four scenarios:

New supplier onboarding. First-batch verification against your specification before full-scale production is standard GMP practice. It catches discrepancies — wrong particle size, unexpected impurity, misidentified botanical — before they affect a finished batch or, worse, a batch already distributed.

Botanicals from documented high-risk origins. Ingredients sourced from regions with known quality variability — certain herbal preparations from China or India, for example — warrant independent heavy metals screening covering lead, cadmium, arsenic, and mercury as a minimum, plus pesticide residue screening where the ingredient’s contaminant history warrants it. The EU’s EFSA has published specific guidance on metals in botanical preparations that safety assessors routinely reference.

Post-incident audits. If a consumer complaint or adverse event triggers a PIF review, current third-party data on the implicated batch demonstrates proactive quality management. It’s often the difference between a corrective action and a recall.

Export to North America. If your products also enter the US or Canadian market, your supplier documentation needs to satisfy different standards. US FDA regulations under 21 CFR Part 700 and the recently expanded MoCRA requirements, or Health Canada’s NHP regulations for supplements, often require analytical data from ISO/IEC 17025-accredited laboratories with specific method validations that your European suppliers may not routinely perform.

Building a Tiered Supplier System That Holds Up in an Audit

Not all suppliers carry equal risk, and applying the same documentation rigour across all of them is neither practical nor required. A tiered qualification approach — borrowed from pharmaceutical GMP but increasingly applied in cosmetics — focuses your effort where the stakes are highest.

Tier 1 (High risk): Active cosmetic ingredients, botanical extracts, preservatives, UV filters, and any material that drives the conclusions in your safety assessment. These suppliers should hold a current third-party GMP certificate (ISO 22716 or equivalent), provide per-batch COAs from an ISO/IEC 17025-accredited laboratory, and be subject to audit — on-site or remote with documented evidence review — at least every 12 to 24 months.

Tier 2 (Medium risk): Functional excipients such as emulsifiers, humectants, thickeners, and carrier materials with limited safety-critical parameters. An annual COA review, current SDS, and up-to-date REACH declaration on file is the baseline. A questionnaire-based audit every 2 to 3 years is typically sufficient unless a change notification is received.

Tier 3 (Low risk): Commodity materials — purified water, simple salts, inert carriers — with well-established safety profiles and minimal contamination risk. Standard COA and SDS on file; audit triggered only by change or complaint.

Document the rationale for each tier assignment. Regulators don’t just want to see what documentation you’ve collected — they want evidence that you applied risk-based thinking to decide what to collect in the first place. A one-page supplier risk matrix, signed and dated, often does more to satisfy an auditor than a thick binder of undifferentiated paperwork.

One practical note: tier assignments should be formally reviewed whenever a supplier changes their manufacturing site, ownership structure, or source material. These events invalidate previous audit conclusions and frequently go undeclared unless you’ve built a proactive change notification requirement into your supply agreements from the start.

Make Your Supplier Files Audit-Ready Before the Auditor Arrives

If there’s a single change that delivers the most leverage for the least effort, it’s adding a “last reviewed” date and a formal re-review trigger to every supplier file. REACH Candidate List updates happen twice yearly. ISO 22716 and ISO/IEC 17025 certificates typically carry 3-year validity with annual surveillance. A COA for a botanical extract purchased in 2023 may bear no resemblance to what you receive in 2026.

A PIF that was complete on the day your safety assessor signed it can slip into non-compliance within 18 months — without a single intentional change, and without anyone noticing until an inspector asks for it.

The brands that sail through DGCCRF inspections aren’t those with the largest documentation files. They’re the ones whose files are dated, versioned, and clearly connected to a living review process. That discipline starts with supplier qualification, and it starts before the product is on the market — not after.


Written by Nour Abochama, Quality & Regulatory Advisor, Care Europe | VP Operations, Qalitex. Learn more about our team

Talk to our team about EU market entry and supplier qualification support. Contact us

Nour Abochama

Yazan

Nour Abochama

Quality & Regulatory Advisor, Care Europe | VP Operations, Qalitex

Chemical engineer with 17+ years of experience in laboratory operations, quality assurance, and regulatory compliance across Europe and North America. VP of Operations at Qalitex (ISO/IEC 17025 accredited US laboratory). Through Care Europe, leads the European entry point to a partner-lab network across the USA, Canada, and local Europe — specialising in USA FDA + Health Canada compliance for European exporters and herbal & supplement testing (a rare expertise on the European continent).

Chemical Engineering17+ Years Lab OperationsISO 17025 ExpertGMP & EU Compliance Specialist
LinkedIn Profilini Görüntüle →

AB düzenleyici danışmanlığa mı ihtiyacınız var?

SIREN kayıtlı Fransız düzenleyici ekibimizden uzman rehberlik alın. İki dilli EN/FR destek.

Teklif İste →