Product Compliance Management: How to Build a Scalable Compliance Process
What product compliance management involves, how to structure the workflow, team, and tools, and how to scale it across markets and thousands of SKUs.
By Complir
Product compliance management is the process of ensuring that every product a company places on the market meets all applicable legal requirements, in every market where it is sold, for as long as it stays on sale. For consumer product companies selling in the EU, that spans product safety under the General Product Safety Regulation (EU) 2023/988 (GPSR), chemical restrictions under the REACH Regulation (EC) 1907/2006, CE marking and conformity assessment, labeling, environmental obligations such as Extended Producer Responsibility (EPR), and the incoming Digital Product Passport (DPP) under the Ecodesign for Sustainable Products Regulation (EU) 2024/1781 (ESPR).
The difficulty is rarely any single regulation. It is running all of them, continuously, across hundreds or thousands of SKUs and multiple markets, with a team that is usually far smaller than the workload implies. This guide covers what product compliance management involves, the six stages of the compliance lifecycle, how to structure the team, where automation fits, and how to build a process that scales with your portfolio instead of breaking under it.
What Is Product Compliance Management?
The definition, the three questions it answers, and the terms you need
Product compliance management is the set of processes, data, and responsibilities a company uses to demonstrate that its products meet every applicable regulatory requirement before launch and throughout their time on the market. It is not a one-time certification exercise. Regulations change, substance lists grow, markets get added, and suppliers switch materials, so compliance is a continuous operating function, not a project.
In practice, product compliance management answers three questions for every product in the portfolio:
- Can I sell this product in this market or channel? Which regulations apply, what evidence exists, and what is missing.
- What must be created to make it compliant? Declarations of Conformity, labels, translations, test reports, technical documentation.
- Why, and what should we do next? Understanding the reasoning behind each requirement well enough to act on gaps and regulatory changes.
Key terminology
- Conformity assessment is the procedure by which a manufacturer demonstrates that a product meets applicable requirements before affixing the CE mark, based on the modules set out in Decision 768/2008/EC.
- Declaration of Conformity (DoC) is the legal document in which the manufacturer declares, on its sole responsibility, that a product conforms to the applicable EU legislation.
- Technical file (technical documentation) is the structured evidence package, including test reports, risk assessments, drawings, and the DoC, that a manufacturer must keep available for market surveillance authorities, typically for 10 years after the product is placed on the market.
- Economic operator is the umbrella term used across EU product law for manufacturers, authorised representatives, importers, distributors, and fulfilment service providers, each of which carries distinct obligations.
- Harmonised standard (EN standard) is a European standard developed at the Commission's request; conforming to a harmonised standard cited in the Official Journal gives a presumption of conformity with the corresponding legal requirements.
Why It Matters
The legal exposure is well known; the commercial exposure hits first
The direct legal exposure is well known. Under GPSR, only safe consumer products may be placed on the EU market, and Member States must lay down penalties that are effective, proportionate, and dissuasive. Market surveillance authorities can require corrective action, order recalls, and remove products from sale under the Market Surveillance Regulation (EU) 2019/1020.
The commercial exposure is usually felt first, and it is growing:
- Marketplace enforcement. Online marketplaces now carry their own obligations under GPSR and request compliance documentation from sellers. A missing document no longer means a theoretical risk; it means a delisted product on Amazon or Zalando.
- Launch delays. A product that is physically ready but missing a DoC, a translated label, or a supplier test report does not ship. For seasonal and trend-driven assortments, weeks of delay translate directly into lost revenue.
- Retail partner requirements. Large retailers increasingly push documentation demands down to their suppliers, with compliance packets required before listing.
- Regulatory acceleration. GPSR has applied since 13 December 2024. The Packaging and Packaging Waste Regulation (EU) 2025/40 (PPWR) applies in general from 12 August 2026. The first mandatory Digital Product Passport, for batteries, applies from 18 February 2027 under the Battery Regulation (EU) 2023/1542. Each new framework multiplies the work for companies still running compliance manually.
13 Dec 2024
GPSR applies
Regulation (EU) 2023/988
18 Jul 2024
ESPR in force
Regulation (EU) 2024/1781
20 Jul 2026
EU DPP registry live
Commission Implementing Regulation (EU) 2026/1778
12 Aug 2026
PPWR general application
Regulation (EU) 2025/40
18 Feb 2027
Battery passport mandatory
Regulation (EU) 2023/1542
2027-2028
Textile DPP delegated act and application
ESPR delegated act, pending adoption
Expected
The scale problem deserves emphasis. A retailer like Flying Tiger Copenhagen introduces around 500 new products per month across 44 countries. At that pace, the question is not whether any single compliance task is hard. It is that no manual process survives that volume. This portfolio-scale challenge is what product compliance management, as a discipline, exists to solve, and it is the problem that led us to build Complir.
The Product Compliance Lifecycle
Six stages from product data to continuous monitoring
Compliance work follows the product. A useful way to structure the function is as a lifecycle that runs from the moment a product is born, as a concept or a supplier offer, until it is market ready, and then keeps running while it stays on sale. Six stages cover the full flow.
Data Gathering
One structured compliance record per product: master data, suppliers, and every document attached and classified.
Classify & Jurisdiction
Map each product to the regulations and standards that apply, per market.
Risk Assessment
A documented risk analysis per product, as EU law expects and volume demands.
Requirements Checklist
Turn classification and risk into assignable, checkable work per product per market.
Execution & Collection
Generate declarations, labels, and translations; collect supplier evidence through structured requests.
Technical File & Monitoring
Keep evidence findable and map every regulatory change back to affected SKUs.
Stage 1: Product and document data gathering
Everything downstream depends on structured product data: what the product is, what it is made of, who supplies it, and which documents exist for it. In most companies this data lives across a PIM system, a PLM tool, spreadsheets, supplier emails, and shared drives, with no single source of truth.
The goal of this stage is one structured compliance record per product: master data, bill of materials where relevant, supplier identity, and every associated document (test reports, certificates, supplier declarations) attached and classified. Without this, every later stage degrades into searching for files.
Stage 2: Classification and jurisdiction mapping
Once a product is described, the next question is which rules apply to it, per market. A children's night light sold in the EU may simultaneously fall under the Toy Safety Directive or the Low Voltage Directive depending on its characteristics, plus GPSR, RoHS, REACH restrictions, WEEE, and packaging rules. Getting this mapping wrong at the start invalidates everything built on top of it.
Classification is traditionally the most expertise-intensive step: someone reads regulatory texts and standards indexes and decides what applies. It is also the step where AI-assisted tooling has advanced furthest, because classification is fundamentally a mapping problem between structured product attributes and a structured body of regulation.
Stage 3: Risk assessment
EU product legislation is risk-based. GPSR requires manufacturers to carry out an internal risk analysis before placing a product on the market, and conformity assessment procedures under CE marking directives are selected according to product risk. A documented risk assessment per product is therefore both a legal expectation and the input that determines how much verification a product needs.
At portfolio scale this becomes a throughput problem. A children's brand entering a new season may need well over a hundred risk assessments at once. The methodology is standard; the volume is what breaks manual processes.
Stage 4: Requirements checklist
Classification and risk assessment translate into a concrete list of requirements per product per market: which tests, which documents, which labeling elements, which registrations. This checklist is the operational heart of the process. It turns abstract regulation into assignable, checkable work, and it is what a launch gate should actually check before a product ships.
Stage 5: Execution, documentation, and supplier collection
This is where most compliance hours are spent: generating Declarations of Conformity, producing compliant labels and translations for every market, and collecting evidence from suppliers.
Supplier document collection deserves its own mention because it is the hidden cost in most compliance budgets. Suppliers, often in Asia, respond late, send the wrong format, or cannot produce a usable DoC themselves. Quality teams burn hours each week chasing emails and re-explaining requirements. A scalable process replaces ad hoc email chasing with structured requests that specify exactly which document is needed, in which format, with automatic classification and gap-tracking on receipt.
“Supplier document retrieval is where generic compliance tools stop and the real work begins. When requests, receipt, classification, and gap-tracking run as one workflow, quality teams review documents instead of chasing them.”
Complir Team
Product Compliance, Complir
Stage 6: Technical file and continuous monitoring
The final stage has two halves. First, evidence storage: every product needs its documentation structured and findable, so that a marketplace request or an authority inspection is an export rather than a scramble. Second, change monitoring: regulations and harmonised standards are updated continuously, and each change needs to be mapped back to the affected SKUs. A process without monitoring is compliant only on the day it was built.
Run in sequence, these six stages form a repeatable pipeline: product is born, data is gathered, rules are mapped, risk is assessed, requirements are listed, documents are produced and collected, and the file stays current. That pipeline, rather than any individual task, is what "product compliance management" means operationally.
Who Owns Compliance?
Three team structures, and two rules that hold across all of them
There is no single correct org chart, but three patterns cover most consumer product companies:
- The embedded owner (small companies, roughly 1 to 50 employees). One person, often a founder, product manager, or operations lead, owns compliance alongside another role. The priority at this size is not headcount but leverage: structured data, templates, and automation that let a non-specialist run a specialist-grade process.
- The compliance function (mid-size, roughly 50 to 500 employees). One to four dedicated quality or regulatory people, usually organized by product category or by market. The recurring failure mode is that each person works their own perimeter in their own spreadsheets, with no unified view. The fix is a shared, structured compliance record per product that everyone works from.
- The distributed model (enterprise). Quality, legal, packaging, sourcing, and market-level teams each own a slice. Coordination, not expertise, becomes the bottleneck, and compliance status per product is hard to answer. What works is a single source of truth with clear stage ownership: sourcing owns supplier documents, quality owns risk and requirements, packaging owns labels, and everyone reads from the same record.
Two rules hold across all three structures. Compliance needs a named owner per product, because shared ownership without a name means no ownership. And compliance must sit inside the launch process as a gate with a checklist, not alongside it as a parallel activity that launches can bypass.
The Six Failure Modes of Manual Compliance
Check which ones describe your current process
If you are assessing your current process, these are the six patterns that most reliably signal it will not scale.
0 of 6 checked
Your process is in good shape. Monitoring and supplier collection are usually the next weak points.
Most teams recognize at least four of these. They are not signs of a weak team; they are signs of a process designed for a smaller portfolio than the one it now serves.
Tools and Automation
The test is output over tracking
The tool landscape splits into four broad categories:
- Generic trackers (spreadsheets, project tools): flexible and free, but they record work rather than doing it, and they collapse at volume.
- Regulatory content databases: strong at telling you what regulations say, weak at connecting that content to your actual products and documents.
- QMS and PLM extensions: good at process control inside their own suite, but compliance is usually a bolt-on rather than the core design.
- AI-native compliance platforms: built to execute the lifecycle itself: classify products, map jurisdictions, generate risk assessments and documents, and run supplier collection.
Whatever category you evaluate, the useful test is output over tracking. A decade of compliance software has produced many systems that remind teams how much work they have. What changes the economics is software that does the work: drafts the risk assessment from the classification, generates the DoC from structured data, produces label translations, and answers questions grounded in your own products and documents, with your team approving rather than typing. Senior quality leads who have lived through a 12-month software implementation that ended in low adoption are right to be skeptical; the burden of proof is on the tool to show generated output in the first demo, not a configuration roadmap.
A practical evaluation checklist:
One record per product
Ingested from your existing PIM, PLM, and spreadsheets rather than re-keyed by hand.
Automatic regulation mapping
Products mapped to regulations and harmonised standards, with change monitoring. For EU consumer products, EN standard coverage matters as much as regulation texts; Complir covers 120+ EN standards.
Document generation
Risk assessments, DoCs, labels, and translations generated from structured data, not just stored.
Supplier collection workflow
Structured document requests with gap tracking, not email threads.
Gap visibility per market
A per-product, per-market answer to "what is missing?"
AI grounded in your data
The assistant works from your products and documents, not a generic chatbot bolted on.
How to Build a Scalable Compliance Process
Six steps, in order
Step 1: Inventory the portfolio and centralize product data
List every active SKU with its category, markets, and supplier. Consolidate documents into one location and attach them to products. This step is unglamorous and it is the foundation for everything else, including future DPP readiness: the Digital Product Passport is, at its core, a structured-product-data requirement, so data centralized now is compliance infrastructure for 2027 and beyond.
Step 2: Map applicable regulations per product category and market
Work category by category, not product by product. Most portfolios cluster into a manageable number of category-market combinations, each with a stable set of applicable regulations and standards. Document the mapping so it is reviewable and reusable.
Step 3: Define the requirements checklist and the launch gate
Translate the mapping into a per-product checklist and make it a formal gate in the launch process. A product does not ship until the checklist is green or a named owner has explicitly accepted the documented risk.
Step 4: Standardize document generation
Template the DoC, label content, and translation workflow so documents are produced from structured data instead of written from scratch. This is typically where teams recover the most hours per launch.
Step 5: Productize supplier collection
Replace email threads with structured document requests tied to the checklist: what is needed, in which format, by when, with automated follow-up and gap visibility.
Step 6: Set up regulatory monitoring and review cadence
Establish a feed of regulatory and standards changes mapped to your categories, plus a periodic review (quarterly for most portfolios) of high-risk products and expiring evidence. This is what turns a compliance snapshot into a compliance process.
If your team is spending its weeks inside the failure modes rather than building these six steps, that gap is what Complir automates: classification, risk assessment, checklists, document generation, supplier collection, and monitoring in one lifecycle.
Frequently Asked Questions
Quick answers to the questions teams actually search
What is product compliance management?
Product compliance management is the continuous process of ensuring every product a company sells meets all applicable legal requirements in every market where it is sold, covering safety, chemicals, labeling, documentation, and environmental obligations, from before launch until the product leaves the market.
What is the difference between product compliance and regulatory affairs?
Regulatory affairs is typically the expertise function: interpreting regulations and defining what applies. Product compliance management is the operational discipline that executes against that interpretation across the whole portfolio: data, checklists, documents, suppliers, and monitoring. In small companies one person does both.
Which regulations does product compliance cover for EU consumer products?
The core set for most consumer products: the General Product Safety Regulation (EU) 2023/988, CE marking legislation where applicable (toys, electronics, PPE, and other harmonised categories), the REACH Regulation (EC) 1907/2006 for chemical restrictions, RoHS Directive 2011/65/EU for electronics, WEEE and other EPR obligations, packaging rules under PPWR (EU) 2025/40, and, progressively from 2027, Digital Product Passport requirements under ESPR (EU) 2024/1781.
What does a product compliance process look like?
A complete process runs six stages: gather product and document data, classify products and map applicable regulations per market, assess risk, translate the result into a per-product requirements checklist, execute (generate documents and collect supplier evidence), and maintain the technical file while monitoring regulatory changes.
Who is responsible for product compliance in a company?
Legally, the manufacturer bears primary responsibility, with importers and distributors carrying their own obligations as economic operators under EU law. Organizationally, responsibility should rest with a named owner per product, whether that is a dedicated quality/regulatory team or an operations lead in a smaller company.
How do you manage compliance across multiple markets?
Build one structured record per product and derive market-specific outputs from it, rather than duplicating the work per market. Classification determines which regulations apply per market; document generation and label translation then propagate from the same record. The anti-pattern is restarting compliance from zero for each new country.
What is a compliance checklist and why does it matter?
A compliance checklist is the per-product, per-market list of concrete requirements (tests, documents, label elements, registrations) derived from classification and risk assessment. It matters because it converts regulation into assignable work and gives launch processes an objective gate.
How does AI change product compliance management?
AI moves compliance software from tracking work to doing work: classifying products against regulations and standards, drafting risk assessments from classification, generating declarations and labels from structured data, and answering compliance questions grounded in a company's own product data. The expert's role shifts from typing to approving. Judgment calls, such as final risk acceptance and lab selection, stay human.
How should companies prepare for the Digital Product Passport?
Structure your product data now. The DPP, introduced by ESPR (EU) 2024/1781, requires structured, accessible product information, beginning with the battery passport on 18 February 2027 under Regulation (EU) 2023/1542, with further categories following via delegated acts. The European Commission's central DPP registry went live on 20 July 2026, with access management, user verification, and data registration rules set out in Commission Implementing Regulation (EU) 2026/1778. Companies with centralized, structured product data will absorb each delegated act as an increment; companies without it will face a data project under deadline.
How many people do you need to run product compliance?
Less a function of headcount than of process and tooling. There is no reliable public benchmark for SKUs per compliance FTE, and any vendor quoting one should be treated with suspicion: capacity varies enormously with product risk category, market count, and supplier structure. What is consistent is the failure pattern: manual processes hit a ceiling where new SKUs outpace the team's ability to produce assessments and documents, and quality erodes before anyone decides to accept that risk. With structured data and automation, small teams run multi-thousand-SKU portfolios: the constraint becomes review capacity, not production capacity.
Related Regulations and Next Steps
Where this hub connects, and what to do now
This guide connects to Complir's regulation-specific guides:
- GPSR, the EU's baseline safety framework for consumer products: GPSR Compliance Guide
- CE Marking, conformity assessment for harmonised product categories: CE Marking Requirements Guide
- REACH, chemical registration and restriction obligations: REACH Compliance Guide
- Digital Product Passport, structured product data requirements under ESPR: DPP Guide
- ESPR, the ecodesign framework behind the DPP: ESPR Explained
- EPR, producer responsibility for packaging, WEEE, batteries, and textiles: EPR Compliance Guide
- PPWR, the EU packaging regulation applying from August 2026: PPWR Compliance Guide
Three takeaways. First, product compliance is a lifecycle, not a checklist: six stages that run from product data to continuous monitoring, and a process is only as strong as its weakest stage. Second, scale is the real adversary: every failure mode described here is survivable at 50 SKUs and fatal at 5,000. Third, the regulatory direction of travel (GPSR enforcement, PPWR in weeks, DPP from 2027) rewards companies that structure their product data and automate execution now.
If your team spends more time chasing documents and re-reading regulations than getting products to market, that is the specific problem Complir was built for: an AI platform that runs the compliance lifecycle from product data to market-ready, with your experts approving instead of producing.
Sources & References
- General Product Safety Regulation (EU) 2023/988: EUR-Lex
- Ecodesign for Sustainable Products Regulation (EU) 2024/1781: EUR-Lex
- Battery Regulation (EU) 2023/1542: EUR-Lex
- REACH Regulation (EC) 1907/2006: EUR-Lex
- RoHS Directive 2011/65/EU: EUR-Lex
- Packaging and Packaging Waste Regulation (EU) 2025/40: EUR-Lex
- Market Surveillance Regulation (EU) 2019/1020: EUR-Lex
- Accreditation and Market Surveillance Regulation (EC) 765/2008: EUR-Lex
- Decision 768/2008/EC on a common framework for the marketing of products: EUR-Lex
- Commission Implementing Regulation (EU) 2026/1778 on the Digital Product Passport registry: EUR-Lex
- "The Digital Product Passport Registry is now live", European Commission, 20 July 2026: European Commission
This article is for informational purposes only and does not constitute legal advice. Regulatory requirements may vary by product category, market, and specific circumstances. Consult with a qualified legal professional for compliance guidance specific to your situation.
Related articles

EU Toy Safety Regulation: What Changed and When It Applies
The new EU Toy Safety Regulation is in force. What changed vs the Toy Safety Directive, deadlines to 2030, and the toy Digital Product Passport explained.

Digital by Default: What Omnibus IV Means for Product Compliance
The EU agreed a 'digital by default' approach to product compliance under Omnibus IV. Here's what changes, and why it's really about data, not documents.

CE Marking Requirements: A Practical Guide for Product Companies
What CE marking requires, which products it covers, how to assess conformity, and what changed in 2025–2026 – explained for product companies.
Launch products globally without compliance bottlenecks.
Complir's AI agents handle the regulations and documentation across every market you sell in - and keep your entire catalogue audit-ready.
