Compliance in global sourcing is not a one-time achievement. It's an ongoing operational function that requires active management — because certifications expire, audit cycles renew, regulatory requirements update, and the factories you've been working with for years don't always tell you when something has lapsed.

Most importers handle this reactively. They discover a lapsed certification when a retailer audit flags it, when a customs hold surfaces it, or when a factory mentions it after the fact. By then the options are limited and the costs are real.

The Gap Between Onboarding and Ongoing

Factory onboarding tends to be thorough on compliance. Before the first order is placed, most professional buyers request and verify certifications — BSCI, Sedex, ISO 9001, product-specific safety certifications, REACH compliance documentation, whatever the category and channel require. The documents are collected, reviewed, and filed. The factory is cleared to produce.

What happens after that initial verification is where most compliance programs break down. The certifications that were current at onboarding have renewal cycles — typically annual or biennial. The factory may or may not renew them on schedule. If they don't, nothing in most buyers' systems generates an alert. The certification quietly lapses, the factory continues shipping, and the gap exists invisibly until it surfaces somewhere inconvenient.

The gap between onboarding rigor and ongoing monitoring is where compliance risk actually lives.

What Expires and When

Different certification types have different renewal cycles, and knowing the landscape matters for building a monitoring calendar.

BSCI and Sedex audits typically run on annual or biennial cycles depending on the factory's risk classification and previous audit scores. A factory with a clean audit history may be on a two-year cycle. A factory with corrective actions may be on annual review. The cycle is set by the audit body — but tracking when the next audit is due is the buyer's responsibility.

ISO 9001 certification requires surveillance audits between three-year recertification cycles. A factory can hold a valid ISO 9001 certificate while being overdue on a surveillance audit — technically in breach of the standard but still presenting the certificate as current.

Product-specific safety certifications — CPSC for children's products, CE marking for products entering the EU, FDA registration for applicable categories — have their own renewal and review schedules. Regulatory changes can also invalidate previously acceptable testing even when the certificate itself hasn't expired.

REACH compliance documentation is particularly nuanced. The underlying regulation updates continuously, and a compliance statement that was accurate two years ago may not reflect current substance restriction lists.

The 90-Day Rule

The minimum lead time for meaningful compliance action is 90 days before expiration.

At 90 days, you have time to request renewal documentation from the factory, follow up if they're slow to respond, escalate if there's a problem with the renewal process, and make decisions about order timing if the renewal is delayed. At 30 days, most of those options are already constrained. At zero days — when the certification has already lapsed — you're in damage control.

A compliance calendar built around 90-day and 30-day alerts before every certification expiration gives you the lead time to manage proactively rather than reactively. The 90-day alert is the prompt to request updated documentation. The 30-day alert is the escalation point if the documentation hasn't arrived.

The Retailer Dimension

For importers selling to major retailers, compliance certification is not optional and the consequences of lapsed documentation are commercial, not just operational.

TJX, Walmart, Target, Burlington, and virtually every significant mass merchant requires current social compliance audits as a condition of doing business. A factory whose BSCI or Sedex certification has lapsed is a factory that cannot legally supply product to those retailers under most vendor agreements. Discovering that lapse after an order is placed — or after product is in transit — creates a problem that has no good solution.

Retailer routing guides often include certification currency as an explicit condition of shipment approval. Some require documentation to be submitted with the advance ship notice. If the documentation isn't current, the shipment doesn't clear — regardless of what the product itself looks like.

Making Compliance Systematic

The importers who manage compliance most effectively treat it as a data management problem rather than a document management problem. The distinction matters.

Document management means storing certificates in a folder and hoping someone remembers to check them. Data management means recording the certification type, the issuing body, the issue date, and the expiration date for every certification held by every active factory — and connecting those records to an alert system that surfaces renewals before they become emergencies.

When compliance data is structured and monitored, the calendar builds itself. When it lives in folders and email threads, it requires someone to maintain it manually — and manual systems break down exactly when things get busy, which is also when compliance gaps are most likely to cause the most damage.

The compliance calendar isn't a complex tool. It's a structured record of what each factory holds, when each certification expires, and who is responsible for requesting renewal. What makes it powerful is that it exists, that it's current, and that it produces alerts early enough to act on.

Have you ever been caught off guard by a lapsed certification at the wrong moment — and what did the gap end up costing? We'd like to hear how you've structured your compliance monitoring since then.