CNCN Ally
← Back to blog
Supplier Verification

How to Verify Supplier Certifications (ISO, BSCI, and More)

CN Ally Team·April 14, 2026

A supplier's certificates are only as trustworthy as your verification. This guide shows how to check ISO, BSCI, SEDEX, CE, UL, and FCC documents against official databases, and what to do when they don't check out.

Ask any experienced importer what a supplier's certificate folder looks like, and they'll smile. ISO 9001. BSCI. CE. SGS test reports. A wall of logos, all in crisp PDF. Some of it is real. Plenty of it isn't, and some of it is real but useless: a genuine certificate for the wrong product, issued to a company with a different name, or expired three years ago.

The problem is not that suppliers lie about everything. Most don't. The problem is that a certificate is a document, and documents can be photoshopped, recycled, or bought from an outfit that never visited the factory. Verifying one takes about half an hour once you know where to look. This guide covers how to check ISO certificates against real databases, what to do with BSCI and SEDEX reports, how CE, UL, and FCC marks actually work (there is no magic CE database), how to verify SGS and TÜV test reports, and what to do when the numbers don't add up.

If you need the broader picture of vetting a supplier from the ground up, start with our supplier verification guide. Certificates are one chapter of it, but it's the chapter where people lose money fastest, so it deserves its own treatment. When importers hit a wall on verification (a body that won't answer, a database in Chinese, a report that looks off), a sourcing agent on the ground in China like CN Ally can run the checks directly.

What a certificate actually proves (and what it doesn't)

Three confusions cause most certificate mistakes, so clear them up first.

A management-system certificate is not a product certificate. ISO 9001 certifies that a company runs a quality management system: documented processes, corrective actions, management reviews. It says nothing about whether a specific product passed a safety test. A supplier can hold a perfectly valid ISO 9001 certificate and still ship you defective goods.

A certificate covers a scope, not the whole company. Every ISO certificate carries a scope statement, something like "design and manufacture of fibreglass sleevings and silicone rubber tubes." If you're buying LED drivers from a company whose scope covers only rubber tubes, the certificate is genuine and irrelevant. The same applies to addresses: a certificate issued for a Shanghai headquarters office does not certify the Dongguan factory actually making your goods. Check the scope and the site address every time.

A certificate is a snapshot with an expiry date. ISO certificates run on a three-year cycle with annual surveillance audits. They get suspended, withdrawn, and allowed to lapse. The PDF in your inbox may have been valid in 2021. Only the issuing body's live database tells you its status today.

Hold these three ideas and the rest of the guide is mechanics.

How to verify an ISO certificate in four steps

ISO 9001 is the certificate you'll see most often from Chinese suppliers, so it's the one to learn thoroughly. The same process applies to ISO 14001, ISO 45001, and other management-system standards.

Step 1: Get the certificate number and the issuing body's name. Ask the supplier for a clean scan. You need the certificate number, the exact legal name of the certified company, the issue and expiry dates, the scope, and the name of the certification body (the company that performed the audit: SGS, TÜV Rheinland, BSI, or a smaller regional body). If the supplier can only send a blurry photo or a certificate with no number, stop there. That's already your answer.

Step 2: Check the body, not just the certificate. This is the step most buyers skip, and it's where fake certification lives. A certificate is only worth something if the body that issued it was accredited by a recognized accreditation authority: CNAS in China, UKAS in the UK, ANAB in the US, and equivalents elsewhere. There is a well-documented market for certificates sold by unaccredited bodies that never audit anything.

Step 3: Search IAF CertSearch. The International Accreditation Forum runs IAF CertSearch, the official global database of accredited management-system certificates. Search by company name or certificate number. The database pulls from more than 2,500 certification and accreditation bodies and shows the certificate's status (active, suspended, or withdrawn), the scope, and the certified sites. It confirms the three things that matter: the certificate is valid, the issuing body was accredited to issue it, and the accreditation body is a recognized IAF member. If the certificate doesn't appear, that alone doesn't prove fraud (not every body pushes data to IAF CertSearch, and publishing can lag). Move to step 4.

Step 4: Confirm with the issuing body directly. Every legitimate certification body maintains a public certificate directory or confirms certificates by email. Contact the body using details from the accreditation register or the body's own official website, never the phone number printed on the certificate you're verifying. Ask for written confirmation of the certificate number, the certified company name, the scope, and the current status. Bodies answer these queries routinely; it's part of their job.

For quick reference, here is the verification route for each document type you'll encounter:

Document · What to check · Where to check it

  • ISO 9001 / 14001 / 45001: Number, scope, sites, dates, status · IAF CertSearch, then the certification body directly
  • BSCI or SEDEX/SMETA audit report: Report ID, audit date, the auditing firm · The auditing firm (SGS, TÜV, Bureau Veritas)
  • CE documentation: Notified-body number if present, EU Declaration of Conformity · The notified body identified by the 4-digit number
  • UL mark: File number, company name · UL Product iQ database
  • FCC grant: FCC ID · FCC equipment authorization database
  • SGS / TÜV / Intertek test report: Report number, product model, standard edition, date · The lab's certificate directory or document verification service

The "bought certificate" problem

Here is the uncomfortable part. In China, as in much of the world, you can buy an ISO certificate the way you'd buy a domain name: quickly, cheaply, and without anyone ever visiting your factory. The certificate looks official. It has a number, a stamp, a signature. It is worthless.

A few tells are reliable:

  • The accreditation logo is missing or unfamiliar. Genuine certificates carry the accreditation body's mark, typically CNAS for Chinese factories, or UKAS/ANAB/DAkkS for others. An unfamiliar logo, or a certificate showing only the certification body's own branding, deserves a hard look.
  • The body isn't in the accreditation registers. Search the certification body's name on IAF CertSearch or the CNAS website. If the body doesn't appear anywhere, the certificate is worth whatever you think a PDF is worth.
  • The scope is suspiciously broad. Vague scope statements like "trading and manufacturing of general products" are a classic sign of a certificate written to please rather than to describe an audited system.

One more nuance: a certificate can be genuine, accredited, and current, yet belong to a different company. Trading companies sometimes display the factory's certificate as their own. The certified legal name must match the company you're contracting with, character for character.

Verifying BSCI and SEDEX audit reports

Social compliance audits (see our social compliance audits guide and the audit types explainer) produce reports, not certificates, and reports verify differently. There is no public database where you can type in a BSCI report number and get a verdict.

The verification route runs through the auditing firm that performed the audit. BSCI audits are conducted by approved firms (SGS, TÜV Rheinland, Bureau Veritas, ELEVATE, and others), and SEDEX SMETA audits similarly. The report names the auditing firm, the audit date, the site audited, and a report reference. Contact that firm directly and ask them to confirm the report's authenticity; they do this for buyers routinely. Ask for the full report, not a summary slide: real SMETA and BSCI reports run dozens of pages with finding-level detail, and a one-page "we passed" summary is easy to fabricate. Check the audit date and site address the same way you check an ISO certificate, and note that social audits carry a defined validity period. A supplier that only ever shows the same two-year-old summary is telling you something.

Verifying product certifications: CE, UL, and FCC

Product marks work differently from management-system certificates, and each has its own traps.

CE: there is no database, and that's by design. The CE mark is not a certificate issued by a central authority. The EU states it plainly: no central body grants permission to use the CE mark. For most product types (electronics under the EMC and Low Voltage directives, machinery, toys), the manufacturer assesses conformity itself, keeps technical documentation, signs an EU Declaration of Conformity, and affixes the mark. So when a Chinese supplier sends a "CE certificate," you usually get either a test report from a lab supporting self-declaration, or an EU-type examination certificate from a notified body for higher-risk products.

Look for the four-digit notified body number next to the CE mark. If it's there, a notified body was involved: find it by its number and confirm the certificate. If there's no number, the product was self-declared, and your target becomes the test report and the Declaration of Conformity: real standard numbers with editions (EN 55032:2015, not just "EN 55032"), a named product and model, a real lab, and a signed declaration. A "CE certificate" from a lab that isn't a notified body, for a product category that allows self-declaration, is just a test report wearing a fancier title. Not necessarily a problem, but you should know which one you have.

UL: check the file number. The UL mark should reference a UL file number, searchable in UL's public Product iQ database: confirm the company, the product category, and the listing status. A UL mark with no file number, or one that doesn't resolve, is decoration.

FCC: check the grant. Electronics sold in the US need an FCC equipment authorization, identified by an FCC ID on the product. The FCC's public equipment authorization search should return the grantee, the product description, and the test reports for that ID. If the ID belongs to a different company or product, the authorization doesn't cover what you're buying.

The common thread: for every product mark, the question is never "does the logo appear on the document." It's "can I find this specific product and this specific company in the authority's own records."

Verifying SGS, TÜV, and Intertek test reports

Test reports are among the most forged documents in China sourcing, because a test report is what stands between a product and a market. The big labs know this and give you verification channels.

SGS maintains a public Certified Client Directory searchable by certificate number, company name, location, or QR code, plus a document verification service where you can submit a full report for confirmation that a document bearing SGS branding is genuine. Check the report number in the directory first; for anything that doesn't appear, submit the document itself.

TÜV Rheinland, TÜV SÜD, and Intertek operate similar certificate databases, each with a searchable directory on its own website. Across all of them the principle is identical: the lab's own database is the authority, not the PDF.

A legitimate test report names specific things a forgery often fumbles: the exact product and model number tested (not the product family), the standard number with its edition year (standards get revised; an undated citation or a superseded edition without explanation needs a follow-up), the lab's location and accreditation basis (commonly ISO/IEC 17025), and specific test and issue dates. Reports are perishable evidence: a five-year-old EMC report for a product redesigned twice since is history, not assurance.

When a report looks right but something nags you, email the lab. Labs verify their own documents as a standing service, usually free, and a two-line email beats a container of non-compliant product. Watch for quiet substitutions, too: a supplier that tested the premium version and ships the cost-reduced one, or a report for the right product from a lab whose name is one letter off the real thing.

What to do when verification fails

Certificates fail verification in two ways, and they call for different responses.

The document is fake, bought, or belongs to someone else. This is usually the end of the conversation with that supplier. Not because one bad document proves everything is rotten, but because of what it says about how this supplier does business. A supplier that forged a test report will forge other things. Our red flags guide covers the broader pattern. Walk away, keep your notes; a supplier that fails once sometimes reappears under a new name with the same documents.

The document is real but doesn't cover what you need. Expired certificate, wrong scope, wrong site, test report for a different model: often fixable. Ask the supplier to explain the gap and provide the right document. A legitimate supplier with a lapsed ISO certificate can usually produce a recertification plan; a factory whose scope covers your product category can request a scope extension. Set a clear deadline. If the right document never materializes, treat it as the first category.

Write down what you found and when. Supplier verification is cumulative: today's notes are the due diligence file that protects you on the next order, as described in the due diligence framework. If a supplier pushes back hard on basic verification requests, that's data too. Legitimate factories answer certificate checks from buyers every week; only the ones with something to hide treat the question as an insult.

Frequently asked questions

How do I check if an ISO 9001 certificate from China is real?

Get the certificate number and the issuing body's name, then search IAF CertSearch by company name or certificate number. Confirm the status is active, the scope covers your product, and the certified sites match the factory. If it doesn't appear, contact the certification body directly using details from its official website, never the contact printed on the certificate.

Can I verify a CE certificate online?

There is no central EU database of CE certificates, because for most products CE marking is a self-declaration by the manufacturer, not a granted certificate. If a four-digit notified body number appears next to the CE mark, contact that notified body to verify. Otherwise, verify the underlying test report with the lab that issued it and request the signed EU Declaration of Conformity.

What does it mean if a supplier's certificate is expired?

An expired ISO certificate means the management system is no longer under surveillance by the certification body: the assurance has lapsed. It doesn't necessarily mean the factory's processes collapsed, but you can't rely on the certificate until it's renewed. Ask for the recertification plan and timeline; if the supplier is vague or defensive, treat it as a red flag.

Are BSCI audit reports publicly searchable?

No. BSCI and SEDEX/SMETA reports are shared through the amfori and Sedex platforms among connected members, not a public database. Ask the supplier for the full report (not a summary), note the auditing firm and report reference, and contact that firm directly to confirm authenticity.

How can I tell if a test report is fake?

Check the report number in the issuing lab's own directory (SGS, TÜV, and Intertek all maintain one). A real report names the exact model tested, the standard with its edition year, the lab location, and specific test dates. Watch for lab names that are one letter off the real thing, missing model numbers, and undated standard citations.

Your 30-minute certificate routine

You don't need to become a compliance specialist. You need a routine, and it fits on an index card: get the number, check the body, search the database, read the scope, confirm the dates. Run every certificate a new supplier sends through those five checks before the first purchase order, and re-check annually. Certificates lapse, scopes change, and companies get bought.

The suppliers worth working with expect this. They send clean scans without being asked twice, they know their certification body's name, and they've answered these questions from other buyers. The ones who stall, who send the same blurry photo for the third time, or who get offended that you asked, have told you everything you need to know.

If you'd rather not spend your afternoons decoding accreditation logos, that's exactly what a verification partner is for. CN Ally runs supplier verification and factory audits across China: certificate checks, on-site audits, and the full due diligence file, so the documents in your inbox get confirmed, not just filed. Write to hi@cnally.com or reach out through the contact page and we'll take it from there.

Need help sourcing this kind of product?

Our team handles supplier verification, QC inspections, and logistics every day.

Get a Free Quote

Ready to source smarter from China?

Tell us what you want to source. We'll reply with vetted factory options and pricing within 24 hours — free, no obligation.