Almost every new customer opens with the same question: "Is this formula compliant?"
Honestly, we can rarely answer that in one sentence. Not because we're dodging it — the question itself isn't specific enough. Compliance was never a matter of one ingredient list passing an inspection. It runs through the formula, the raw materials, testing, packaging, documentation, market entry, and keeps running after the product is already on shelves. Drop the thread at any point, and it doesn't matter how well everything before it was done.
That's also why we don't particularly enjoy talking about compliance. Not because it doesn't matter — it matters precisely because there's no getting around it. It's just tedious, repetitive, and you're constantly digging up a six-month-old file over one small detail. There's not much fun in it. Honestly, before we sat down to write this piece, we were dreading it — compliance is the kind of topic where the moment you start writing, you know you're taking apart a pile of details with no clean finish line, not the kind of subject where you get to show off a bit of craft the way you can with formulation.
This article breaks compliance into nine layers, in the order a real OEM project actually moves through them — starting with the most basic question, "is this even legal," and working through the formula, testing, packaging, documentation, market entry, and the ongoing changes that keep happening after a product ships. It ends on a question that gets overlooked constantly: being legally allowed to sell something is not the same as being able to sell it.
If you're looking for a simple yes or no, this probably isn't the article for you. But if you want to know exactly how many checkpoints a product has to clear between formula and market — and what each one is actually checking for — here are the nine layers, one at a time.

Layer 1: Legal Compliance — The Product Must Be Legal Before Anything Else
The first layer of cosmetic compliance is legal compliance. The question is simple: can this product be legally sold in the target market?
But "every ingredient in the formula is legal" and "this product is legal" are not the same statement. The law doesn't just look at the ingredient list. It looks at what the product actually is, who it's sold to, how it's used, how much is used, and how it's marketed. Miss one of these, and the whole judgment can be wrong.
1. First, Work Out What This Product Actually Is
The first step in compliance isn't checking INCI names — it's confirming product classification. The same formula, with a different claim attached, can land in a completely different regulatory framework.
A standard moisturizing cream is normally just a cosmetic. But the moment it claims to treat eczema or be antibacterial, the game changes. The question is no longer "can these ingredients be used in cosmetics" — it's whether the claim has pushed the product into drug, OTC drug, or biocide territory. Sunscreen is the same trap in a different form: the EU regulates it as a cosmetic, the US regulates it as an OTC drug — same product, two entirely different paths.
Sometimes the problem isn't the claim at all — it's the product's physical composition. Take a "bath bomb + toy" combo set: the bath bomb portion falls under cosmetics regulation, but the toy portion has to independently satisfy the Toy Safety Directive (2009/48/EC) — a completely separate compliance system. It's easy for a customer to think "this is just a bath bomb" and miss the toy half entirely. We'll come back to this exact combo set further down — once we get to who is legally responsible for signing off on it, in Layer 7.

So before real development starts, three things need to be nailed down: what the product is, where it's sold, and what it's going to claim. Without these, every compliance judgment that follows is built on shaky ground.
2. Whether an Ingredient Is "Allowed" Is Never a One-Line Answer
Once the product category and market are set, ingredient compliance comes next — and it's never a simple banned/not-banned question. Concentration, where on the body, who it's for, whether a warning is required: each one can flip the answer. We walk through exactly how this review actually works, ingredient by ingredient, in Layer 3.
3. "Natural" Is Not a Free Pass
This is the single most common misconception on any project: "It's natural, so it should be fine."
Essential oils, plant extracts, natural colorants — they all still have to clear concentration limits, fragrance allergen rules, and photosensitivity checks. Even "food-grade" doesn't save you: food regulation is concerned with what you swallow; cosmetic regulation is concerned with what sits on your face, around your eyes, every day, for months. It's not the same logic at all. Natural fragrance is the clearest example of this trap — worth its own explanation, so we've kept that for Layer 3.
What formula review actually cares about is what the substance is, how much is used, how it's applied, and how the regulation defines it — not whether the word "natural" appears on the label.
4. An INCI Name Doesn't Tell You Everything About a Raw Material
This is one of the most underestimated points in OEM projects: an INCI name is not the full picture of a raw material. A commercial raw material is very often a package deal — active, solvent, carrier, and preservative bundled together. A formula that reads Raw Material A — 2.00% does not mean the finished product contains 2% of that single INCI. We'll show exactly how this plays out with a real supplier document in Layer 3.
5. Finishing the Formula Doesn't Finish the Legal Work
A clean formula review doesn't mean legal compliance is done. Product name, function, ingredient list, net content, warnings, who the Responsible Person/Party is, whether notification is required — every market has its own requirements. A product with a perfectly legal formula can still be blocked from the market by one missing line on the label, the wrong responsible entity, or a notification that never got filed. Who actually carries that responsibility, and what it takes to prove it, is its own long story — we'll pick it up properly in Layer 7, once the product is ready to actually enter a market.
The Core of Legal Compliance Isn't a "List of Banned Ingredients"
Compressed into one working sequence for an OEM project, it looks like this:
Target Market → Product Classification → Intended Use & Claims → Labeling & Mandatory Information → Notification / Registration Requirements
So when a customer asks "Is this formula EU compliant?" — a formula sheet alone can't answer that. You first need to know what the product is, how it's used, what it's going to claim, and where it's going to be sold. Only once all of that is clear does the word "compliant" actually carry any weight.
Layer 2: Start With the Target Market — Set the Direction Before You Finish All the Compliance Work
At the start of a project, we usually only ask the customer one question: Where will the product be sold?
That's not asking the customer to have every regulatory detail figured out before development starts. A real OEM project is never a straight line — "confirm regulations → develop formula → test → package → register." Formula, raw materials, packaging, testing, and labeling usually move together, interleaved. A lot of projects begin with nothing more than: "We want to develop a natural body lotion for the EU market." That's already enough — it's incomplete, but it's enough to start development, because it gives the project a regulatory frame.
The target market gives you a direction, not an answer.
1. Why Knowing the Target Market Early Matters
Because a lot of product decisions get pulled by the market from day one. Hear EU body lotion, and we can already rough out the category, the regulatory framework, and which tests and documents to prepare. Hear US sunscreen, and the whole development logic changes. Hear EU children's body lotion — still a lotion, but the weight given to use-on-children considerations, ingredient selection, and warnings shifts immediately.
The easiest place to fall into this trap is children's products. Plenty of projects start without the customer ever saying it's for children — the formula gets finalized, the sample gets confirmed, and only at the final stage, when ingredient data is being submitted for the compliance file, does it turn out that a few ingredients aren't suitable for children's products and need to be removed or replaced. By then the sample is already confirmed. It's no longer a one-line label fix — it's re-prototyping from scratch. That kind of rework is entirely avoidable, if "this is for kids" gets said on day one.
We ask about the target market not to fill out a checklist, but to keep the project from heading in the wrong direction from the start.
2. Not Everything Needs to Be Locked on Day One
Some information is better known early — target market, product category, intended use, target consumer (especially special populations like children), and any claim that could shift the regulatory classification. Nail these down, and the direction of development is stable.
Other information is meant to develop along with the project: final fragrance, final color, final packaging, artwork, INCI list, label wording. Without a fragrance, you can't do a fragrance allergen review. Without packaging, you can't do a label review. Without a locked formula, there's no accurate final INCI list. Sometimes a customer asks for a complete regulatory package right at project kickoff — but at that stage, a lot of that documentation simply doesn't exist yet. What we can provide is reference material from existing products; the rest gets filled in as the formula, fragrance, packaging, and claims are each finalized.
OEM compliance is a progressive process: the product takes shape gradually, and the documentation catches up gradually too.
3. Formula Development and Compliance Review Usually Happen at the Same Time
We rarely finish all the regulatory work first and then hand it off to R&D. It's more common for two tracks to run in parallel: R&D locks the formula while we check key ingredients at the same time; the customer picks a fragrance, and we pull IFRA and allergen information alongside it; once packaging is set, we start calculating net content and label space; once a claim is confirmed, we check whether the wording holds up.
The workflow looks closer to this:
Target Market Identified → Formula Development ↔ Ingredient Review ↔ Claims Review ↔ Raw Material Documentation ↔ Fragrance/Color Selection ↔ Testing ↔ Packaging Development ↔ Label Review → Final Compliance Check
These steps pull on each other — new information in one often changes the judgment in another.
4. Going Back to Change Something Doesn't Mean Something Went Wrong
A customer says "our retailer won't accept this ingredient," and the formula has to be adjusted. A customer asks, mid-packaging, "can we put 'antibacterial' on the front?" — and that one word can pull in a product classification and claim review. A customer says "we also want to sell into the US now," and the compliance scope originally built around the EU has to expand. None of these are mistakes — they're the project receiving new information.
An OEM project is never a production line that only moves forward. It's closer to a loop: Develop → Review → Adjust → Confirm → Continue.
5. What Happens When the Same Product Needs to Enter a Second Market
You don't default to redeveloping from scratch. Start by running the existing product back through the new market's regulatory framework: classification, formula restrictions, concentration conditions, claims, labeling requirements, existing test reports and documentation. If both markets' requirements line up, the formula can usually carry over — just update the label and paperwork. Where they differ, adjust for the specific gap — sometimes that's just the label, sometimes it's the formula itself. The more markets involved, the more conditions have to be satisfied at once. Whether to pursue a so-called "global formula" ultimately comes down to actual sales plans, not the pursuit of a theoretical one-size-fits-all.
6. The Earlier a Requirement Surfaces, the Cheaper It Is to Deal With
This is where Start With the Target Market pays off in practice. Learn during formulation that a retailer won't accept a certain ingredient category — just design around it. Learn during fragrance selection that a customer has an allergen policy — factor it in while picking the fragrance. Learn during packaging that the product needs to enter multilingual markets — leave room on the label up front. These problems, on their own, usually aren't hard to solve. What actually drives up cost is finding out about a requirement after the product is already locked — a small change ends up pulling on the entire chain:
Formula → Sample → Testing → Packaging → Artwork → Documentation → Production Schedule
The earlier a requirement shows up, the easier it is to design around it. The later it shows up, the more it turns into rework after the fact.
Target Market Is a Direction, Not an Isolated Step One
A real OEM project isn't a straight line. Target Market functions more like the foundational input for the whole project — it pulls on the formula, ingredients, claims, fragrance and color, testing, packaging, labeling, and documentation, and these elements keep influencing each other throughout development as the customer provides new information.
So instead of a straight line like "Market → Compliance → Formula → Packaging → Registration," it looks closer to this:
Target Market → Define the Initial Compliance Scope → Develop + Review + Adjust → Final Product & Compliance Confirmation
Start with the market, then build compliance into the development process.
Layer 3: Formula & Ingredient Compliance — Regulation Has to Land Inside the Formula
Once the target market is set, compliance moves properly into product development.
But we don't take a formula and sort every ingredient into an Allowed / Banned column. The base raw materials commonly used in this industry have already been filtered through regulation, supply stability, and cost — most of what's left isn't really in dispute. The real judgment call is never "is this INCI in the regulatory database" — it's: do these raw materials, at their current levels and used this way, add up to a formula that's actually fit for the target market?
Formula compliance isn't a one-time ingredient search. It's screening that keeps happening throughout development.
1. What Gets Reviewed Is the Formula — Not the Ingredient List the Customer Sees
The customer might just see a line that reads Aqua, Glycerin, Niacinamide..., but the review works off the manufacturing formula with real percentages. Here's the key point: Raw Material % ≠ INCI %. A commercial raw material is rarely a single INCI — and to make things worse, a supplier's own different documents for the same raw material sometimes can't even agree with each other on composition.
Here's a real example we ran into with a supplier's Sorbitol:
COA (tested per Chinese national standard GB 1886.187-2016): Sorbitol (C6H14O6) content 50.9%, moisture 29.4%
MSDS (Composition section): Sorbitol, CAS# 50-70-4, % by Weight: 100

Same supplier, same batch — two documents that flatly disagree on composition. One says roughly a 51% solution; the other says 100% pure. This isn't a rounding issue: if formula review only looked at the MSDS and calculated concentration off Sorbitol 100%, a formula line reading Sorbitol — 5% would actually put only about half that much pure Sorbitol into the finished product — the rest is water. That directly changes the water-phase ratio, the preservative system calculation, and even the final INCI ordering.
This kind of contradiction usually isn't a supplier hiding something — it's that MSDS documents are often filled out from a generic template without adjusting for the fact that the material is actually a solution. The COA is the document that actually reflects what was tested on this batch. Compliance review can't trust just one document. When the COA and the MSDS disagree, you correct with the tested data — you don't run formula calculations off the nominal composition. This is exactly the same trap flagged back in Layer 1 as "an INCI name doesn't tell you everything" — here's what it actually looks like on a real document.
2. Whether an Ingredient Is "Allowed" Is Never a One-Line Answer
For ingredients that need attention, we never just ask "Is it permitted?" — we also ask at what concentration, in what product, on what part of the body, for whom, and under what conditions. The same ingredient can face one set of restrictions rinse-off and another leave-on; something usable in adult products may not be for children's products; something usable at all may require a warning. So when a customer asks in isolation, "is this ingredient compliant in the EU," we often can't just say yes or no — whether it's compliant usually depends on how it's used, not on the ingredient itself.
In practice, though, it's not as tangled as it sounds. If an ingredient has any doubt attached to it — even something as minor as bad reviews online, nowhere near an actual violation — we'll often just drop it rather than fight that battle. The condition is two things: a substitute is available, and the cost works. This isn't the opposite of rigorous review — it's simply not worth taking on a risk that could be avoided entirely, just to prove an ingredient is "technically fine."
3. Not Every Ingredient Deserves the Same Level of Scrutiny
A mature formula might have twenty or thirty INCIs, but they don't all get reviewed from scratch. Base materials like Aqua and Glycerin obviously aren't in the same attention tier as a preservative, a colorant, or a UV filter. So the real review is risk-based — we put the effort where things actually tend to go wrong:
Preservatives. Approved substance list, maximum concentration, conditions of use (we cover this in more depth in Why Phenoxyethanol Is the Default).
Colorants. Permitted range often tied to product category, area of application, and target market.
UV filters. The regulatory path can be completely different depending on the market.
Fragrance. A single line reading Parfum on a formula sheet says nothing about its internal composition; that has to be filled in with IFRA and allergen information. Worth flagging here: the EU's individually-declarable fragrance allergen list just got much longer — Regulation (EU) 2023/1545 expanded Annex III from the long-standing 26 substances to roughly 82, and full enforcement began on 31 July 2026. An allergen review built against the old list is no longer complete.
Restricted / high-activity ingredients. Anything with a defined concentration limit or warning requirement has to be calculated precisely.
It's not the same checklist run against every ingredient — it's finding where the risk actually sits, then digging in there.
What Actually Gets Checked in a Formula
Where a cell reads N/A, the check genuinely doesn't apply under current regulation — it isn't a gap in the review.
4. "Natural" Is a Trap That's Easy to Underestimate at the Formula Level
A natural origin doesn't exempt something from compliance — we covered that in Layer 1. Here it's worth singling out natural fragrance specifically, because it's the easiest one to get wrong. Customers often assume "natural fragrance is simpler than a regular one — no need to check it" — the opposite is true. A natural fragrance is still built from a mix of natural aromatic substances, essential oils, or extracts, and the fragrance allergens naturally present in it are no fewer than in a synthetic one. It needs the same look at composition, IFRA certificate, allergen declaration, and actual usage level. "Natural" never means no restriction, no allergen, no review.
5. A Formula Has to Clear More Than Just Regulation
Once a product is actually in a commercial project, there's another layer of restriction that comes from the customer and the retailer themselves: blacklists, clean beauty standards, certification requirements. Regulation permits Phenoxyethanol — a customer can still require Phenoxyethanol-free. Regulation doesn't ban PEGs — a customer can still say No PEGs. These aren't law, but they're just as binding a boundary on formula design.
"Is PEG banned in the EU?" and "Can we use PEG in this project?" are two different questions — the first is regulatory, the second also depends on the customer's and the channel's own standards. So the actual usable formula space is the sum of several layers stacked together: regulatory requirements + target market conditions + customer/channel restrictions + certification requirements + product positioning. This is why two products can both claim to be "EU Compliant" and still have completely different formula structures.
6. Formula Review Isn't a One-Time Deal
Passing once doesn't mean you never look again. Swap an ingredient, change a concentration, change the preservative system, change the fragrance, change the colorant, change a supplier, change a claim, change the market — any one of these can overturn the original conclusion. Not every change requires redoing everything, though: switching to a supplier with matching specs and complete documentation usually has limited impact; but once composition, impurity levels, the preservative system, or active content actually change, the original conclusion has to be re-checked to see if it still holds.
So formula compliance works more like a loop: Develop → Review → Modify → Re-check Where Necessary → Lock Formula. A locked formula is what everything after it — testing, safety assessment, labeling, documentation, production — is built on.
Formula Compliance Draws a Boundary — It Doesn't Hand You an Answer
Compressed into one working sequence, it isn't Ingredient Database → Pass/Fail. It's:
Target Market → Product Type & Intended Use → Manufacturing Formula + Actual Addition Levels → Understand Commercial Raw Material Composition → Identify High-Attention Ingredients → Check Limits & Conditions of Use → Apply Customer / Retailer Requirements → Adjust Where Necessary → Lock the Formula
Regulation doesn't decide what a good formula is for R&D — it just draws a boundary around the space R&D gets to work in. Inside that boundary, texture, efficacy, stability, cost, consumer experience, and manufacturability still have to be weighed on their own merits. Outside it are the options this project simply isn't allowed to touch.
Formulation decides what works. Compliance defines where we are allowed to work.
Layer 4: Safety & Product Testing — Beyond Formula Compliance, the Product Itself Still Has to Prove Out
Passing ingredient compliance review doesn't mean development is finished. Regulatory review answers "can these ingredients be used this way" — but a real finished product still has to answer: can it stay stable? Will it change after manufacturing and shipping? Is the microbial risk actually under control? Can the packaging and the formula coexist long-term? Do the claims we're planning to make have anything backing them up?
Formula Compliance asks: are we allowed to formulate it this way? Product Testing verifies: does the finished product actually work safely as intended? These are two different questions — don't mix them up.
1. There's No "Standard Testing Package" That Fits Every Product
Customers often ask "what tests do you usually run" — that's answerable. But the real question is "what tests does this product need" — and the answer always depends on the product itself. A water-based lotion and an anhydrous balm have different testing priorities — an anhydrous formula, for instance, contains no preservative at all, so a Challenge Test (which verifies whether the preservative system actually holds up) simply doesn't apply. That's not a test being skipped; it's a test that has no meaning for that formula system in the first place. An adult shower gel and a leave-on product for infants carry different risk logic. A plain moisturizing claim and something like SPF or antibacterial — which need hard evidence — are an entirely different matter. The testing plan follows the product type, the formula system, the microbial risk, the packaging, the intended use, the target population, the claims, the market, and any additional customer/retailer requirements. Testing follows the product, not a universal checklist.
2. The Three Areas That Cause the Most Problems: Stability, Packaging Compatibility, Microbiology
We've already broken these down in detail in our article Cosmetic Testing Before Production (test items, timelines, and costs are all covered there) — here we'll just cover the key judgment logic without repeating it:
Stability. This isn't testing whether "the sample looks normal" — it's whether the product can "stay itself" after manufacturing, shipping, storage, and repeated heat/cold cycles. The value isn't in getting a PASS report; it's in surfacing problems early.
Packaging Compatibility. "This bottle is PET" doesn't substitute for a compatibility judgment. Formula discoloration bleeding through, a pump that won't depress, a gasket swelling — these are all problems that come out of the specific combination of bottle + pump + gasket + decoration + formula. Same material doesn't mean same result.
Microbiology / Challenge Test. Having Phenoxyethanol in the formula doesn't equal "microbiologically safe." Microbial limits testing answers "is this batch clean right now"; a Challenge Test answers "does the preservative system actually hold up." These are two different questions — don't treat them as one.
3. A "Natural Formula" Often Means More Testing Is Needed, Not Less
This is a fairly common counterintuitive point on projects. A customer wanting natural, preservative-free, and a high botanical extract content isn't a problem on its own — but the inference "natural = safer" often doesn't hold up at the testing level. A high load of botanical extracts can actually bring more complex color change, odor change, batch-to-batch variation, microbial load, and oxidation risk. If a customer wants Natural + Water-based + Preservative-free all at once, the real question is: how does this product plan to control microbial risk? "Natural" is never a reason to reduce testing — often it's the opposite.
4. Testing Happens Progressively, and Failure Is a Normal Part of Development
Testing doesn't wait until the product is fully finalized to begin: the first prototype can already be checked for appearance, pH, and preliminary stability; once the formula is mostly locked, it moves into formal stability or microbial assessment; once packaging is set, compatibility testing follows; if the fragrance or color changes at the last minute, earlier results have to be re-confirmed as still valid. The workflow looks closer to Prototype → Internal Observation → Formula Adjustment → Preliminary Testing → Formula/Packaging Confirmation → Final Validation — not "finish the formula, hand it all to the lab, done."
A failed test doesn't mean a failed product, either. Viscosity drops at high temperature — that tells you a particular system needs adjusting. A pump fails after repeated use — switching pumps might solve it without touching the formula at all. A Challenge Test doesn't meet the standard — go back and look at preservative dosage, the blend, the pH, or the packaging, then test again. Test → Find Problem → Adjust → Re-test is simply the normal process. The point of testing was never to prove you got it right the first time — it's to squeeze the problems out before mass production.
5. Not Every Product Needs Every Test Run on It
Patch test, dermatological test, moisturization test, consumer test — these don't all get applied to every product the same way. One customer making a plain moisturizer might only care that it feels hydrating. Another customer wants to print "Dermatologically Tested" on the pack — which requires a third-party test report to back it up. Those are already two different project requirements. So we don't default to assuming "every product needs every test we're capable of running" — we wait until the product, the market, the claims, and the customer's requirements become clear, then decide what verification to add. The question was never how many tests a product could run — it's which tests are actually relevant to this product, this project.
Testing Isn't an Administrative Step That Comes After Compliance — It's Part of Development Itself
Compressed into one working sequence:
Formula Developed → Identify Product Risks & Project Requirements → Determine Relevant Testing → Test While Development Continues → Find Problems → Adjust Formula or Packaging → Re-test Where Necessary → Final Product Validation
Compliance tells us what is permitted. Testing helps us verify whether the actual product performs as intended and remains suitable through its expected use.
Layer 5: Packaging Compliance — The Package Itself Is Also Part of Product Compliance
The previous layer covered Packaging Compatibility: whether this formula and this package cause problems together. But even when compatibility is completely fine, there's a totally different question — is this package itself suitable for this product, in this market? That's Packaging Compliance.
This is exactly the kind of question customers ask most often on a project: Can we use PCR plastic? Is this paper + PE pouch recyclable? Can you provide a material declaration? These all sound like they're asking about "packaging material," but underneath, they can be pulling on completely different layers of requirement. So Packaging Compliance is never a simple mapping of PET = compliant, PP = compliant — what actually has to be reviewed is the whole packaging system.
1. A Package Is Never Just One Material
The customer might just see a bottle of lotion, but the packaging structure usually hides an entire set of components — Bottle, Pump, Dip Tube, Spring, Gasket, Label, Adhesive, Printing, Coating — each made of a different material: PET, PP, PE, metal, rubber, adhesive, ink. So when a customer asks "What material is this packaging?" we first need to know whether they mean the main bottle material or the entire packaging structure. Breaking it down as Bottle: PET / Pump: PP / Dip Tube: PE / Spring: Stainless Steel is always more useful than a single line reading Material: PET — a lot of regulatory, environmental, and buyer requirements were never just about the main bottle. Heavy metal limits (the EU's PPWR — Regulation (EU) 2025/40, which replaced the older 94/62/EC — and Toxics in Packaging laws in multiple US states) and REACH SVHC declarations are, in principle, both assessed per individual component — not averaged out across the total weight of a pump.
Honestly, this is something I only worked out later myself — on projects, I've gotten used to customers repeatedly asking for pigment test reports on the bottle, but almost nobody ever asks whether the plating on the metal spring inside the pump is compliant. At first I assumed customers just hadn't thought of it. Then I looked into TPCH's (the US Toxics in Packaging Clearinghouse) own screening data, and it turned out to be more complicated than that: the real hotspots for violations are printing inks, color pigments, and flexible PVC (often used as a heat stabilizer) — lead concentrations found in plastic bag printing inks have measured up to 20 times the regulatory limit. In other words, the risk was never tied to "is this a bottle or a pump" — it follows wherever coloring, printing, and plating actually happen. Bottles have historically been more prone to violations simply because the bottle is usually the component that gets decorated and colored. So the thing worth telling a customer was never "the bottle matters more than the pump" — it's that the moment custom color or plating gets used on a pump, the risk moves with it, and the customer's attention often doesn't follow.

2. What Packaging Material Compliance Actually Has to Look At
Different projects weight this differently, but a few things always have to be covered:
What the material actually is — PET, HDPE, PP, glass, aluminium, laminated structure...
Whether restricted substances or heavy metals are present — the most basic step, and also the easiest one to skip.
If PCR is used, the actual recycled content and its source have to be documented — not just labeled with a percentage.
Surface treatment counts as part of the finished package — plating, screen printing, hot stamping, coating; none of this is automatically covered just because the main bottle is compliant.
Same material, different product, different result — alcohol, essential oils, and high-oil formulas each place different demands on packaging material.
The target market may have its own environmental regulations — packaging waste, recyclability, and producer responsibility requirements vary by market.
Any one of these could easily be its own article. For now, the one thing worth remembering is: packaging compliance is based on the actual packaging structure, not simply the name of the main material.
3. "Is This Material Compliant" Is Rarely a Simple Yes or No
A customer asks "Is PP compliant?" PP itself is common enough, but the question doesn't have enough information — used where (the bottle body, the cap, the pump, or one layer of a multilayer structure)? Holding what product (body lotion or a high-alcohol product)? Sold where (EU/US/UK/Australia)? Is the customer actually worried about chemical restrictions, recyclability, PCR content, PPWR, or the retailer's own requirements? This is the exact same logic we covered for ingredient compliance in Layer 3 — you rarely just ask "is this ingredient compliant"; you have to look at ingredient + concentration + product + market. Packaging works the same way: Material + Structure + Product + Market + Intended Claim/Requirement — all five together decide what actually needs reviewing.
4. Packaging Compliance Documentation Also Comes From the Supply Chain
Same logic as raw materials: an OEM factory isn't the original producer of resin, glass, ink, or adhesive — a lot of the compliance documentation ultimately has to come from the packaging supplier: material specifications, composition, supplier declarations, heavy metal/restricted substance information, recycled content declarations, test reports. Stock packaging documentation is usually fairly complete; but once custom color, coating, metallized pumps, or special printing get involved, there's noticeably more to confirm. This is also why we can answer "is this bottle PET" instantly, but can't turn that one answer into a promise that "the entire packaging meets every requirement of your target market" — those aren't the same question.
5. Environmental Requirements and Packaging Compliance Are Getting Harder to Separate
Packaging discussions used to center on "can this material safely hold this product." Now customers increasingly ask: is it recyclable? Can PCR be used? What's the plastic content? Does this structure satisfy the PPWR? Can PE be swapped for PP? These questions have already extended from traditional packaging specs into the entire domain of recyclability, material reduction, recycled content, waste management, and environmental claims — and that domain itself is still moving fast.
A paper + plastic laminate pouch can't be called "paper packaging" just because the outer layer is paper. A pump bottle with a PET body can't have its recyclability judged on PET alone either — what matters is still the complete material structure. PPWR, PCR, and mono-material design each deserve their own deep dive; for now, remember that packaging has to answer two questions at once: "can it do its job" and "does it meet the target market's material and environmental expectations."
From Packaging Compliance to Labeling Compliance
Once the packaging structure and material direction are set, the next question is: what actually needs to be written on the finished pack? That's Labeling Compliance — here we'll just establish two basic ideas.
6. The Label Has to Match the Actual Product
Ingredient list, net content, warnings, directions, and company information — these mandatory items ultimately have to correspond to what's actually being manufactured. Change the formula, and the label has to be re-checked. Change the fragrance, and the INCI/allergen information may need to change with it. Change the packaging spec, and the net content has to be recalculated. Change a claim, and the artwork has to be re-reviewed. Label review was never about whether the design looks good — it's about whether this line of text actually matches the real product.
7. Label Compliance Isn't Just Mandatory Information
The marketing claims on the front of a pack — Natural, Dermatologically Tested, Antibacterial, Vegan, Sensitive Skin — are just as much a part of the finished product's expression, and can just as easily pull in claim substantiation, product classification, or a customer/retailer's own extra requirements.
The trickiest part is the claims a customer assumes are obvious but that simply don't hold up. Whitening is the classic case — we get asked from time to time whether we can make a "whitening facial cleanser," and honestly it's an awkward conversation every single time: the whitening claim doesn't hold up under most markets' regulatory frameworks to begin with, and setting regulation aside, actually achieving it within a safe formulation is far from easy technically. Anti-aging and hair growth claims fall into the same category — they sound like perfectly reasonable product goals, but once you get down to the formula and the regulation, it's a completely different matter. You can certainly find products like this being sold, especially in markets with looser enforcement — but that doesn't mean the claim itself would hold up to scrutiny. It just means a regulatory gap exists there.
Packaging carries the product. Labeling explains the product. Together, they're what the consumer is actually buying. Details like ingredient declaration, warnings, multilingual labeling, claims, and artwork review are covered in more depth in a dedicated Labeling Compliance piece down the line.
Packaging Is Another Interface Between Formula and Market
Connecting the layers so far:
Target Market → Formula & Ingredient Compliance → Safety & Product Testing → Packaging Compatibility → Packaging Material & Structure Compliance → Labeling & Product Information → Market-Ready Product
A compliant product requires the formula, the packaging, and the information presented to the consumer to work together.
Layer 6: Documentation & Product Dossier — Turning Product Development Into Something That Can Be Proven
The layers so far dealt with "how should this product be made." With Documentation, the question becomes: how do we prove that what actually got manufactured is the same product that was reviewed, tested, and confirmed earlier?
Customers often ask "Can you provide all compliance documents?" — but on an OEM project, "all compliance documents" is never a ready-made ZIP folder sitting on a factory computer. A lot of this documentation only gets generated once the formula, raw materials, testing, packaging, and artwork are each finalized, one by one. Documentation isn't something added on after development is finished — it grows out of development itself.
1. "Compliance Documents" Is Never a Fixed List
When a customer asks "what compliance documents can you provide," the underlying purpose is often completely different depending on who's asking. Some are just doing initial due diligence on the factory and the product — they want INCI/SDS/COA/IFRA. Some are working on EU market entry — what they actually need is documentation that can support a CPSR/PIF/CPNP. Some are working on a retailer project — they'll also need test reports, restricted-substance declarations, and packaging information. There's also a category of customer — especially the ones who found us through Alibaba — who are looking to buy an in-stock item, and default to assuming "this is already sitting out there being sold, so all the compliance work must already be done." That assumption is often wrong: in-stock products usually have basic SDS/COA/INCI, but documentation like CPSR and PIF — which is built around a specific finished product and a specific market — very often simply doesn't exist yet, because no customer has ever actually needed it before. So we never think of Documentation as "one product = a fixed set of 20 documents." The more accurate logic is: Product + Target Market + Customer/Retailer Requirement → Required Documentation.
2. Getting From a Pile of Upstream Documents to a Finished-Product Dossier Takes a Layer of Calculation In Between
Take an ordinary body lotion as an example: the formula contains Emulsifier A — 3%, Preservative Blend B — 0.8%, Fragrance C — 0.5%, and Botanical Extract D — 2%. The supplier documentation first has to answer a few specific questions:
Emulsifier A — what INCIs does it actually contain?
Preservative Blend B — what's the actual concentration of active preservative it contributes to the finished product?
Fragrance C — which IFRA category does it fall under, and what allergens does it carry?
Botanical Extract D — besides the plant extract itself, is it also cut with glycerin, water, or a preservative?
Once this information is sorted out, it gets built up layer by layer: Raw Material Composition combines into the Final Manufacturing Formula, from which the Final INCI List is calculated; the formula plus product characteristics produce Finished Product Specifications like appearance, odor, pH, and viscosity; the formula plus testing produces Stability, Microbiology, and Challenge Test reports (and it has to be clearly stated which version of the formula was tested); the formula plus packaging produces the Packaging Specification; and finally, formula + packaging + claims + mandatory information come together to produce the Final Artwork.
(We already broke down the logic that "a commercial raw material isn't a single INCI" in A Cosmetic Formula Is a System, so we won't repeat it here.) Finished Product Documentation isn't supplier files simply piled together — it's calculated and mapped, layer by layer. Only at this point can we genuinely say: "This is the product we are going to manufacture."
3. What an OEM Actually Delivers Is a Technical Product Package
What a manufacturer provides is never just the SDS + COA + INCI trio. A complete OEM technical package typically covers the following, built up progressively over the course of the project:
Product identity information — name, type, intended use
Formula information — final formula, final INCI, raw material composition
Product specifications — appearance, odor, pH, viscosity, fill specifications
Safety and test evidence — stability, microbiology, challenge test, compatibility
Fragrance/ingredient supporting documents — IFRA, allergens, supplier declarations
Packaging information
Finished product information — directions for use, warnings, claims, final artwork
Not every product ends up with the same combination of documents, but once these are put together, they're no longer scattered supplier certificates — they constitute the technical identity of this finished product.
4. Why We Usually Can't Provide "Complete Finished-Product Documentation" at the Start of a Project
Because a lot of decisions haven't happened yet. A project might start with nothing more than a base formula; fragrance-related documents only get added once the customer settles on a fragrance; the final formula only exists once the formula has been tested, adjusted, and locked; test reports only get added once testing is complete; packaging documents only come in once packaging is set; and finished-product information is only in place once artwork is confirmed. Documentation follows the same Develop → Confirm → Generate Evidence → Update Documentation sequence as the development logic in the earlier layers. So when a customer asks for "the complete PIF / full registration package" on their very first inquiry, it's often not that we're withholding it — it's that the product hasn't been fully defined yet, and its complete documentation simply doesn't exist. What can be provided at the early stage is the base formula or reference material from existing products; the final regulatory package has to be built on the final product.
5. A Technical Product Package Is Not the Same as the Final Market Regulatory Dossier
This is a distinction that's easy to blur on OEM projects. What the manufacturer builds is the product's technical foundation — formula, raw material information, test reports, packaging information, product specifications — which becomes an important basis for the safety assessment and PIF that follow. But a CPSR isn't something a factory generates automatically by stapling together supplier PDFs; it requires a dedicated safety assessment. A PIF isn't "the manufacturer's standard folder" either — it's a regulatory dossier built around a specific finished product. And depending on the market, the division of roles between the Responsible Person, the Importer, and the Safety Assessor can look completely different. The manufacturer's responsibility is to provide accurate, complete, traceable technical information; the market regulatory process is a separate thing that continues from there, built on top of that information.
6. One More Question That Can't Be Avoided: Version Control
Say a project goes through Formula V1 → adjusted due to a stability issue → V2 → fragrance changed again → V3 (the final version). At that point, the documentation has to be built around V3 — if the Challenge Test was run on V2, you have to judge whether the change from V2 to V3 affects the original conclusion; if the fragrance changed, the IFRA and allergen information has to be updated; if the packaging supplier changed, the packaging documentation has to be re-confirmed. If the artwork still reflects V2's ingredient list, then even though every individual document is true on its own, the package as a whole is inconsistent. So the real question when reviewing Documentation was never "do we have an SDS" — it's: Does every important document point to the same finished product?
Documentation Is Where All the Preceding Work Converges
Connecting the layers so far:
Target Market → Formula & Ingredient Compliance → Safety & Product Testing → Packaging & Labeling → Technical Product Documentation → Market-specific Regulatory Dossier → Notification / Registration
Documentation was never an independent sixth item on its own — it's what collects, connects, and verifies the information generated by the five preceding layers, ultimately assembling it into a technical foundation capable of supporting market compliance. What matters was never how many documents there are, but whether they can clearly answer: what is this product, exactly? What is it made of? What evidence backs it up? Which version of the packaging and label does it belong to?
Once documentation can answer these questions clearly, Layer 7 can really begin: what else do we have to do to legally get this finished product into the target market?

Layer 7: Market Entry & Regulatory Handover — How Technical Documentation Actually Turns Into Market Access
By Layer 6, we've assembled a Technical Product Package that describes the finished product: final formula, raw material documents, product specifications, test reports, packaging information, final INCI/artwork. But having a complete folder doesn't automatically qualify the product to enter the target market. What actually happens next is: this technical documentation starts feeding into the regulatory process specific to the target market.
The specific system varies by market — safety assessment, product dossier, Responsible Person, notification, registration — the names and processes differ. But from an OEM manufacturer's perspective, the core logic is one line:
Technical Product Package → Regulatory Review → Market-specific Requirements → Questions/Additional Information → Final Assessment & Documentation → Notification/Registration Where Required → Product Placed on the Market
Market Entry doesn't replace the work that came before it — it puts the documentation built up so far to use.
1. What the Manufacturer Provides Is the Technical Foundation for Market Entry
The formula tells the reviewer what the product is actually made of; raw material documents explain the composition, active content, and fragrance information that need reviewing within commercial raw materials; test reports provide stability, microbiology, and challenge test results; packaging information describes the actual structure and materials; product specifications define the state the final product is meant to be manufactured in. Put together, these documents form the technical foundation for market entry — but on an EU project, this same documentation also has to be used to support the safety assessment, the PIF, and CPNP notification; in a different market, the way it's organized can look completely different. So what we hand over is never a "registration certificate" — it's the technical information the product needs to complete the target market's entry process.
2. Market Entry Usually Takes Several Roles Working Together
By this stage, the manufacturer is often no longer the only party involved in compliance — Brand Owner, Importer, Responsible Person, Safety Assessor, Regulatory Consultant, and even the customer's own compliance team may all be involved at the same time. The typical relationship looks like this:
Manufacturer provides technical product information → Safety Assessor reviews whether the product meets market requirements → Brand/Responsible Market Entity confirms commercial and market information → Market-specific Dossier is formed → Notification/Registration
(Exactly how these roles divide the work, and how CPNP notification actually proceeds, is something we've already broken down in detail in CPNP, PIF, CPSR, so we won't repeat it here.) In reality, these roles are often moving at the same time, not lined up this neatly. But one line is clear: the manufacturer knows how the product was made; the market-entry process decides how this product gets assessed, recorded, and placed on the market. The two have to connect — they don't replace each other.
3. Who Is Legally "the Manufacturer" — and Why a Test Report Can't Stand In for a Declaration of Conformity
This distinction trips up almost every project at some point, so it's worth spelling out on its own:
A customer gets a third-party test report, then follows up with: "Could you also provide a Declaration of Conformity?" The factory's first reaction is usually: "We already sent the report — why do we need another document?"
That reaction is understandable, but it doesn't hold up. A test report and a legal declaration are two fundamentally different kinds of documents, answering two different questions:

Test Report — a technical document from a third-party lab. Proves one thing: what the results were, for this specific sample, on these specific standard tests.
Declaration of Conformity (DoC) — a legal document signed by the manufacturer or responsible person. Declares the entire product meets all of the directive's essential safety requirements, and puts a name and signature behind that claim.
A test report on its own doesn't put the company on the hook for the entire product or the whole shipment, and it doesn't cover anything the directive requires beyond those specific tests — chemical restrictions, warning labels, instructions, traceability marking, and so on. A DoC, meanwhile, also lists the harmonized standards being referenced and states who the responsible party is. It's the legally binding commitment a company makes to market surveillance authorities and to its customers — the mandatory document that allows a compliance mark to be applied and the product to be legally sold in the target market. A test report can be cited inside it. It can't replace it. The customer isn't being difficult here: if market surveillance carries out a spot check, the retailer needs to be able to produce the DoC immediately to show the compliance chain is intact — and if they can't, the retailer is the one who gets held liable.
This friction keeps happening for a simple reason: "passed the test, technically" and "who is legally on the hook" are not the same question in a factory's everyday thinking. The legal definition of "manufacturer" is also broader than people assume: a company that integrates a third-party-made component or product into its own final product, and sells it under its own name, is legally considered the "manufacturer" of that final product — even if it never physically made that component. "We subcontracted that part out" doesn't remove the responsibility.
This is exactly the bath bomb + toy combo set from Layer 1. Sold to an EU customer, the supply chain looks like this:
Toy factory (makes the toy) → You (assemble the toy into the bath bomb, package it as the final combo set) → EU customer (imports and sells it)
You're the one placing the combined product on the EU market as a single unit — so you, not the toy factory, are normally the one who should sign the DoC as the manufacturer. What you need from the toy factory isn't "a DoC the toy factory signed" — it's the toy's own test reports and material/structural technical data, which you then use to support the DoC and technical file you issue yourself. If the manufacturer isn't based in the target market, an EU Authorized Representative or an importer can take on the signing responsibility instead — but the responsibility itself doesn't disappear just because "we only assembled it" or "we subcontracted it."
4. Regulatory Review Often Kicks Questions Back to the Supply Chain
This is a very practical part of the Market Entry stage. No matter how complete the technical documentation is, new questions can still come up once it actually enters review. A Safety Assessor looks at a commercial raw material and asks for "the full composition" — the manufacturer then has to go back to the raw material supplier for composition, specification, and regulatory declaration. Fragrance comes under review and the latest IFRA Certificate and allergen information are requested — back to the fragrance house. A Responsible Person reviewing artwork finds a warning line that needs changing, and that's a round of Regulatory Review → Artwork Revision → Client Confirmation → Final Artwork Updated. Packaging works the same way — the reviewer wants more material information, and the question loops back to the packaging supplier. So Market Entry is rarely as simple as "submit the documents, get approved" — it's closer to a back-and-forth:
Technical Package → Regulatory Review → Question → Trace Back to Manufacturer/Supplier → Provide Additional Evidence → Update Documentation → Continue Review
The more solidly the documentation chain from the earlier layers was built, the smoother this back-and-forth goes. If all that was collected early on was a scattered handful of SDS and COA documents that can't answer "what is this finished product actually made of," the problem tends to surface right here.
Honestly, "going back to ask the supplier" is often not as easy as it sounds. A lot of raw material suppliers — especially smaller domestic ones — manufacture to Chinese regulations and standards, and are neither familiar with EU or US requirements nor see any need to be: as far as they're concerned, they sell raw materials, not finished products, so meeting the national standard is enough. Language is another barrier — a lot of suppliers' technical documentation only exists in Chinese, and their sales staff can read a purchase order but not a Safety Assessor's line reading "Please provide full composition and IFRA-compliant allergen breakdown." So this back-and-forth often can't be closed with a single message: the customer's or reviewer's requirement has to be translated into something the supplier can understand, and then whatever the supplier sends back has to be reorganized into the format the other side's regulatory system expects. As the finished-product supplier, a large part of what we actually do is bridge this gap between the customer and the raw material supplier — and the gap that already exists between different regulatory systems.
One practical question that comes up often here: can Chinese-language documentation be used directly to support a CPSR? The answer is yes, but "supporting documents" and "the CPSR itself" are two different things. At the regulatory level, supporting documents within a PIF — lab reports, supplier declarations, and the like — are allowed to stay in their original language; they don't have to be translated into English before they can be filed. But that doesn't mean Chinese-language documents can directly constitute a CPSR: a CPSR is a conclusory document a qualified Safety Assessor produces after synthesizing information and making a safety judgment — it's not a stack of raw documents. The real bottleneck was never "can the documentation be kept in Chinese" — it's whether the assessor themselves can accurately understand the content and make a correct judgment based on it.
So can machine translation solve this? It can be a first step, but not the last one. Structured data — INCI names, CAS numbers, GHS hazard codes, specific concentrations — machine translation handles fine, and a lot of Chinese-language SDS documents already keep this part in English or international codes anyway. Where it's genuinely easy to go wrong is the free-text portions — special conditions of use, which INCI in a preservative blend is actually doing the work and at what concentration, or a mistranslated negative (for example, "not recommended for use around the eyes" getting flipped into "recommended for use around the eyes"). These are exactly the parts a safety assessment relies on most — mistranslate one negative and the conclusion can flip entirely, and a machine-translated sentence that reads smoothly makes people let their guard down, so the error doesn't stand out. So submitting Chinese and English side by side is the right approach, and it's what we recommend — but the English version should still be checked by someone who understands both the technical content and Chinese; a raw machine-translation output shouldn't just get attached as-is.
That said, this check ultimately only counts as a reference, not a certification. Whoever checks the translation, even if they understand both chemistry and Chinese/English, isn't a certified translator, and certainly isn't a Safety Assessor in the regulatory sense — what this step can do is reduce the odds of an error at the source and make the material the assessor receives more reliable, not "we've reviewed it, so this translation is fine." The person who is actually responsible for the safety conclusion, and who has to hold the relevant professional qualification, remains the Safety Assessor who signs the CPSR — the chain of responsibility doesn't shift or lighten just because someone in the middle checked a translation. Regulatory responsibility can't be substituted by how conscientious any one link in the chain happened to be — whoever is supposed to be responsible, still is.
5. The Product Actually Placed on the Market Has to Match the Product That Was Reviewed
Even after review is passed, there's still a very practical question: is what we end up mass-producing actually the same product that was reviewed in the first place? If the safety assessment was based on Formula V3, mass production has to use that corresponding final formula. If the fragrance documentation was based on Fragrance A and it later got switched to Fragrance B, the related documents and assessment need to be re-evaluated for whether they need updating. If the packaging information was based on a PET Bottle + PP Pump and the packaging structure changes significantly, the existing documents need to be re-checked for whether they still apply. If the artwork that was reviewed was V4, the printed production run absolutely cannot end up using V2 because of an internal version-control mistake. At this point, the formula, raw materials, testing, packaging, artwork, and regulatory documents all have to point to the same finished product. So Market Entry was never just asking "is notification done" — it also has to make sure the product actually placed on the market is the same thing that was originally assessed and recorded.
6. Getting Registered Doesn't Mean Compliance Work Is Over
Once a product is finally on the market, it's easy to assume the regulatory work is wrapped up. But for an OEM product in ongoing production, the real question is just starting to shift into: the next time something changes, does the whole process need to be run through again? That question is exactly what the next layer is dedicated to.
Market Entry Is the First Real Test of Everything Built So Far
Connecting the layers so far:
Target Market → Legal & Product Requirements → Formula & Ingredient Compliance → Safety & Product Testing → Packaging & Labeling → Technical Product Documentation → Regulatory Review ↔ Manufacturer/Suppliers → Market-specific Dossier → Notification/Registration → Product Placed on the Market → Ongoing Compliance
This is the point where we genuinely move from "can this product be developed" to "can this specific finished product be placed on the target market." Registration was never a compliance shortcut — what actually supports Market Entry is the formula, evidence, packaging, labeling, and documentation already built up in the layers before it. Once a product is on the market, the question shifts too — no longer just "is it compliant," but an ongoing one: "has anything changed that could affect its compliance status?"
Layer 8: Ongoing Compliance & Change Control — Managing What Keeps Changing After a Product Is on the Market
Finishing Market Entry doesn't mean compliance is permanently done. A commercial product can stay in production for years, and over that time, the supply chain is almost never going to sit still — raw material suppliers change, fragrance houses adjust their formulas, packaging suppliers change, a raw material spec gets updated, regulations and retailer requirements shift. So once a product is on the market, compliance stops being a development project and becomes Ongoing Compliance Management.
Here's the very practical problem, though: an OEM factory might be managing hundreds of formulas, raw materials, packaging components, and long-running SKUs at once. If every single upstream change automatically triggered the full sequence — "notify the customer → regulatory re-review → re-test → update documentation → update market filings" — management cost would explode almost immediately, and a huge amount of effort would go into routine changes that don't actually affect the finished product's compliance at all. So the goal of Change Control was never to stop change, or to escalate every single change — it's to answer one question: what did this change actually alter, does it matter, and how far does the impact reach? All of this, of course, rests on one non-negotiable precondition: risk management operates inside regulatory requirements — it never substitutes for them. Regulations, certification requirements, and customer-approved specifications are themselves the boundary that change control operates within.
1. A Supplier Change Doesn't Mean the Product Changed — But the Same INCI Doesn't Mean the Same Raw Material
Take a Body Lotion already in stable mass production as an example. The formula contains Glycerin — 5.0%, originally from Supplier A, now being switched to Supplier B because of lead time or supply issues. The first question here isn't "should we notify the customer" — it's: does this supplier change actually change the raw material or the finished product from a compliance standpoint? If the new supplier has already passed qualification, and the specification, SDS, COA, and required regulatory information have been reviewed with no material difference found, this change is most likely just "an equivalent substitution within an already-approved raw material spec." A Supplier Change Record, the new supplier's documentation, and an equivalency assessment, followed by normal incoming QC, is enough — there's no need to restart the entire finished-product compliance process just because "the supplier's name changed."
But take a different example: the formula's Botanical Extract X — 2.0% — Supplier A's commercial raw material is actually composed of Plant Extract + Water + Glycerin + Preservative A. Switch to Supplier B, and the main plant INCI on the label might look exactly the same, but pull it apart and the composition is now Plant Extract + Water + Propanediol + Preservative B. A customer might assume "it's still the same plant extract" — but from a manufacturing formula and regulatory assessment standpoint, what's actually going into the finished product has changed. Did the preservative contribution change? Was a new substance introduced? Does the Final INCI need to change with it? Are there new conditions of use? Does the original safety assessment still represent this product as it now stands? Could stability or preservative efficacy be affected? The same INCI name on a purchase order doesn't mean the same compliance outcome. A change like this has to be escalated from an internal supplier change into a real Formula/Regulatory Impact Assessment, which then decides whether the formula documentation, Final INCI, testing, Safety Assessor/Responsible Person review, or artwork need updating. The difference between these two examples is exactly what Change Control is meant to deal with.
2. The Core of Change Control Is Impact Assessment, Not Notification
The logic compresses into one line:
Supplier Change → Collect New Supplier Information → Compare Composition/Specification/Regulatory Status → Assess Impact on the Finished Product
Changes with no material impact go through an internal change record, updated supplier documentation, and normal QC, and production continues; changes with potential or material impact get escalated to a Regulatory Impact Assessment, which decides — based on actual impact — whether additional testing, RP/Safety Assessor/customer involvement, or updates to market filings or artwork are needed. The goal of change control was never to escalate every change — it's to identify which changes genuinely need escalating.
In practice, there's no need to run every change through the exact same process either — it makes more sense to tier changes by their level of impact:
Routine Change — e.g. switching Glycerin suppliers, where an equivalency assessment confirms no material change to composition, safety, or regulatory status. Stays within internal control.
Relevant Change — a raw material spec, blend composition, or packaging component changes, but the impact isn't fully clear yet. Needs a technical evaluation, with follow-up verification or documentation updates where necessary.
Material Change — the preservative system changes, INCI composition changes, active concentration changes, fragrance/allergen profile changes, the formula changes, a claim changes, or regulatory status changes. Goes to a full Regulatory Impact Assessment, which decides based on actual impact whether testing, the CPSR/PIF, artwork, or filings need updating.
The point here isn't to slap a "tier one, two, three" label on every change — it's establishing the decision path of "internal control → technical review → regulatory escalation."
3. The Real Question Is Where the Impact Stops, Not Whether Something Changed
A customer says "we only changed the fragrance." Change Control shouldn't mechanically respond "then redo everything" — it should trace down the impact chain:
Fragrance changed → Did composition/IFRA/allergen profile change? → Did the Final INCI change? → Is the safety assessment affected? → Is the artwork affected? → Are existing market filings affected?
If the impact stops at some point along that chain, there's no need to restart everything downstream just because "a change happened." But if the impact genuinely reaches all the way to the safety assessment or market filings, it has to keep being processed from there. Don't just ask whether something changed — ask where the impact stops.
4. Regulation Is Always the Hard Boundary Change Control Cannot Cross
Risk management doesn't mean the manufacturer gets to decide which regulatory requirements to follow and which not to — those are two different things: regulation draws the boundary; risk assessment decides how to move within it. For example, if the maximum use level for a preservative gets lowered, a company first has to trace the impact chain to find out: which raw materials contain it? Which formulas use those raw materials? Which SKUs are affected? Which markets are affected? What is legally required? If the regulation requires reformulation, a changed warning label, or an updated safety assessment, high management cost is not a reason to keep things as they are. Likewise, if a certification, a customer-approved specification, or a mutual agreement explicitly states that "a supplier change requires prior approval," that itself is a change-control requirement of the project. Cost affects how efficiently compliance is managed — it doesn't get to redefine what compliance actually requires.
5. After Launch, External Changes Can Also Reopen a Product
It's not only internal changes that happen — the external environment changes too: regulatory updates, updates to a retailer's restricted-substance list, shifting customer requirements, updated certification standards, and even ongoing consumer complaints, packaging leaks, discoloration, odor changes, or retailer quality complaints that surface after launch. None of these necessarily mean the product has a compliance problem right now, but they can constitute new information that needs to be re-evaluated: could this situation undermine the assumptions or evidence the original assessment of this product relied on? If the answer is yes, the relevant compliance review has to be reopened.
6. Long-Term Compliance Ultimately Depends on Traceability
This is also why the earlier layers kept emphasizing Documentation. Suppose a substance in a raw material suddenly gets restricted by a new regulation — the manufacturer has to be able to trace back quickly through the supply chain:
Substance → Commercial Raw Material → Formula → SKU → Customer → Target Market
That's the only way to know which products actually need action, rather than re-reviewing every single product. Traceability was never just about "having complete paperwork" — its real commercial value is bringing down the long-term cost of compliance management.
This is also where the real gap between manufacturers opens up. Traceability is never as simple as a folder of documents — behind it is a web woven from technical capability (can you break a commercial raw material down to its INCI composition), regulatory capability (knowing which changes need to be traced upstream, and how far), and management capability (can supply chain information actually be kept up to date and pulled up on demand) — and if any one of the three is missing, the web breaks. Customers sometimes ask: it's the same body lotion, so why can the quotes differ so much? Aside from the formula's raw materials and process, a large part of the remaining difference is hiding in exactly these invisible places.
Ongoing Compliance Isn't About "Nothing Ever Changing"
In the real world, the supply chain will change — raw materials change, suppliers change, packaging changes, regulations change. So a mature OEM compliance system shouldn't be built on "nothing is allowed to change" — it should be a path that can be walked over and over:
Change → Document → Assess → Handle Internally Where That's Enough → Escalate Where That's Needed → Update Only What's Genuinely Affected
What's actually wanted isn't zero change — it's that change can happen, but stays controllable, traceable, and within the bounds of regulatory requirements at all times.
This is also the most realistic balance in long-term Compliance Management: the regulatory boundary can't be compromised; risk assessment decides how far a change is allowed to go; traceability tells us which products are genuinely affected; and change control is what lets a product that's been on the market for years keep standing on solid compliance ground, even as its supply chain keeps changing underneath it.
Getting a product compliant is a project. Keeping it compliant requires a system that is both rigorous and workable.
Layer 9: Buyer & Retailer Requirements — Legal Does Not Always Mean Sellable
By this point, a product may have gone through a genuinely complete compliance process: the formula is legal, the ingredients have been reviewed, safety and stability have been assessed, packaging and labeling have been checked, the technical documentation is in place, and the necessary market filings are done. From a regulatory standpoint, this product is very likely able to legally enter the target market.
But for an OEM manufacturer, there's still one very real question left: will this specific customer, this specific sales channel, actually accept it? The answer isn't automatically yes. Law draws the basic boundary for what can be placed on the market, but brands, retailers, certification schemes, and distribution channels often layer their own requirements on top of that. Legal compliance defines what can be placed on the market; buyer requirements define what this specific customer or channel is willing to accept — and these two circles are often not the same one.
1. Legal Doesn't Mean Sellable — A Customer's Restriction List Can Directly Shrink the Formula Space
Suppose an ingredient is fully permitted, its concentration is compliant, it suits this product type, and the safety assessment raises no issues — from a regulatory standpoint, it's completely fine. But the customer might simply say "we don't allow this ingredient," or the retailer's restricted-substance list excludes it. The result: the regulatory status is "yes," the buyer status is "no." This doesn't mean the regulatory judgment was wrong — it's just that buyer standards can be narrower than regulatory restrictions. So judging whether a formula "can be made" actually involves two different questions — can it legally be formulated, and can it be formulated within this customer's requirements — and the two can't be answered as if they were one.
This gap often directly changes the usable formula space. Say the regulatory range allows A+B+C+D+E+F; the customer's own restriction list excludes C and E, leaving A+B+D+F; the retailer adds "no D," and what's left is just A+B+F. So a commercial formula was never facing a single set of regulations — it's facing:
Regulatory Requirements ∩ Target Market Requirements ∩ Customer Restriction List ∩ Retailer Requirements ∩ Certification Requirements ∩ Product Positioning
This is exactly why two equally legal formulas can end up with one getting into a given retailer and the other not.

2. "Clean Beauty" Requirements Are, More Often Than Not, Not Actually Law
OEMs regularly get requests like Phenoxyethanol-free, PEG-free, Paraben-free, or 100% natural, but the reasons behind them vary widely — some are brand positioning, some are retailer policy, some are certification requirements, and some are pure consumer preference. Plenty of the ingredients being excluded would be perfectly legal to use under regulation. So "is this ingredient compliant" and "can this ingredient be used at this retailer" are two different questions — the first checks regulation, the second checks the buyer's or retailer's requirements. "This customer won't accept it" doesn't mean "it's not compliant"; and conversely, "regulation allows it" doesn't mean "it's commercially usable."
3. The Closer to a Major Retail Channel, the More Specific This Layer of Requirements Usually Gets
This gap becomes more obvious as a product heads toward a major retail channel. A retailer may have its own restricted-substance list, ingredient policy, packaging requirements, testing requirements, quality standards, sustainability requirements, and even its own artwork/claim review process. So the question stops being "can this product be sold in Germany" and becomes "can this specific product be accepted by this specific retailer in Germany" — two entirely different compliance questions. EU regulation may allow a given ingredient, but a retailer's restricted list excludes it, and the result is: legally sellable in the EU ✓, but not sellable at this retailer ✗. This is why major retail projects so often run into a situation where the product hasn't violated any regulation and still needs reformulating — not because it isn't compliant, but because it doesn't meet the buyer's requirements. That distinction matters.
4. Certification Is Another Separate Layer of Rules — and It's Best Brought In Early
Once a customer wants COSMOS, NATRUE, Vegan, or Organic certification, the product enters an entirely separate set of entry standards — an ingredient might be regulatorily permitted but not accepted under the certification scheme, or the ingredient itself might be fine but the raw material sourcing, processing method, supplier documentation, or percentage calculations don't meet the certification's requirements. At that point, the question is no longer a matter of checking INCIs — it's whether this formula, these raw materials, and this supply chain can actually support the standard. So certification shouldn't be treated as "get the product compliant first, then apply for the certificate as an afterthought" — if a certification is going to restrict ingredient choices, it needs to come into formula development earlier, which is exactly the principle stated back in Layer 2: the earlier a requirement shows up, the easier it is to design around it, rather than turning into rework after the fact.
5. A Buyer Requirement Also Has to Be Specific and Actionable — Not Just a Vague Phrase
On the other hand, manufacturers also regularly receive vague requirements like "clean formula," "EU standard," or "non-toxic," which are hard to translate directly into formula instructions. "Retailer compliant" first requires knowing which retailer — if the customer has an explicit restricted list, ingredient policy, packaging guidelines, or testing specifications, the most effective approach is never guessing what a given retailer probably doesn't like, but looking at the actual requirements. "Clean Beauty" likewise isn't one globally standardized regulatory bar — different brands and retailers can define it in completely different ways. A buyer requirement that's genuinely executable should be translatable into specific restricted ingredients, maximum use levels, required claims, required certifications, required tests, packaging requirements, and documentation requirements — only a requirement that lands on an actual product decision is a useful one.
6. Buyer Requirements Never Replace Regulatory Compliance
There's a clear line to draw here too. If a customer's restricted list is stricter than regulation, we can certainly develop within that stricter range — but meeting the buyer's requirements doesn't mean everything is settled. A customer saying "we just need these 20 ingredients excluded" doesn't substitute for a full regulatory review — the product still has to meet all applicable regulations, ingredient restrictions, safety requirements, labeling requirements, and other market-entry obligations. So the relationship between the two sets of requirements is: legal compliance first draws the basic boundary for what can enter the market; within that boundary, buyer/retailer/certification requirements then further narrow the commercially usable space — the order can't be reversed. Buyer standards can be stricter than the law, but they can never replace it.
From Compliant to Market-Ready
Having gone through all nine layers, what we've actually built is a path far more complex than "run through an INCI check once":
Target Market → Legal Requirements → Formula & Ingredient Compliance → Safety & Product Testing → Packaging & Labeling → Technical Documentation → Market Entry → Ongoing Compliance & Change Control → Buyer/Retailer Requirements → Market-Ready Product
This is also why we're rarely willing to answer "Yes, this product is compliant" based on an ingredient list alone — real product compliance was never an isolated ingredient judgment call. It has to answer all of the following at once: what is this product? Where is it sold? How is it used? What's actually in the formula? Does the safety and stability data hold up? Is the packaging suitable? Does the label match the product? Does the technical documentation actually support market entry? If the product changes, can compliance still be maintained? And finally — will the target buyer or sales channel actually accept it?
Compliance Is a System, Not a Certificate
For an OEM/ODM manufacturer, compliance was never about getting a customer a certificate, or a final check the regulatory team runs once development is finished. Compliance that actually works stays continuously involved from the very start of a project — through the formula, the raw materials, testing, packaging, documentation, market entry, production, and all the way through the change management that follows. At the same time, it has to face a commercial reality: the range regulation permits is often wider than the range that's commercially acceptable. Regulation tells us where we're allowed to work; buyers, retailers, and certification requirements then tell us where this specific product needs to work. A product that can actually get to market and keep selling has to satisfy both boundaries.
If this whole article had to compress into one sentence, it would be this: Cosmetic compliance is not a final checkpoint. It is a system that connects formulation, safety, packaging, documentation, market entry and commercial requirements throughout the life of a product.
From an OEM's perspective, what we're actually doing is continuously answering the same set of questions within this system: can we formulate this product? Can we prove it's safe? Can we legally sell it? And — will the target market actually accept it?


.jpeg)


