Skip to content

Compliance

Digital Enforcement: Your Compliance PDF Is Obsolete

The traditional model of compliance enforcement was manual and slow. A regulator received a complaint, opened an investigation, requested documents by letter, and reviewed them months later. A customs officer physically inspected a shipment, checked the paperwork against the goods, and made a decision at the port. A buyer sent a supplier questionnaire, received a PDF attachment, and filed it in a procurement folder.

That model is dying — and not just in one region. Globally, compliance enforcement is moving from paper to digital, from manual to automated, from reactive to real-time. The PDF attachment that satisfied a buyer audit in 2020 is no longer sufficient in 2026, because the platforms, regulators, and customs authorities that enforce compliance have moved to systems that require structured, verifiable, digitally accessible data.

How to Publish a WCAG Accessibility Statement

If you run a website or app in the EU, UK, or Canada, an accessibility statement isn't optional — it's the law. Even where it isn't legally required, publishing one is the single cheapest way to reduce your ADA litigation risk and signal to users that you take inclusion seriously.

An accessibility statement is a public declaration of your conformance level, what you've done to meet it, and how users can contact you if they encounter barriers. This guide covers what to include, which jurisdictions require one, and how to keep it from going stale (which is where most organisations fall down).

Compliance & Sustainability: Two Worlds Becoming One

In most businesses, compliance and sustainability report to different executives, use different software, collect different data, and attend different conferences. Compliance owns the legal obligation — the product safety certificates, the chemical declarations, the import filings. Sustainability owns the voluntary narrative — the carbon footprint, the ESG report, the supplier diversity metrics.

That separation is ending. Regulations across every major market are requiring the same data that both functions need — and building separate systems to satisfy the same regulatory demand is no longer tenable.

In Europe, the CSRD requires audited sustainability disclosures against over 1,100 data points. In the United States, California's SB 253 and SB 261 require climate emissions and risk disclosure from companies doing business in the state. The SEC's climate disclosure rule — currently stayed but directionally clear — will require public companies to report Scope 1, 2, and in many cases Scope 3 emissions. Australia's mandatory climate reporting framework, phased in from 2024 onward, requires financial-disclosure-grade climate data from large entities. China's dual-carbon policy (碳达峰, 碳中和 — "carbon peak, carbon neutrality") is driving mandatory environmental disclosure through the China Securities Regulatory Commission and the Ministry of Ecology and Environment.

The global direction is unambiguous: sustainability reporting is becoming compliance.

WCAG: Web Content Accessibility Guidelines

If you run a website, app, or digital service, you're probably already required to comply with WCAG — even though it isn't a law itself. The Web Content Accessibility Guidelines (WCAG) are the global standard for digital accessibility, and they've been incorporated into legal frameworks across the EU, UK, US, Canada, and Australia. You don't have a choice about whether to follow them; you only have a choice about whether you comply proactively or reactively after a complaint.

Developed by the W3C's Web Accessibility Initiative, WCAG covers visual, auditory, physical, speech, cognitive, language, learning, and neurological disabilities. It's the closest thing to a universal accessibility rulebook the world has.

What to Ask Suppliers Before They Get You Fined

If your supplier uses forced labor, the goods are seized at the US border — and you are the importer of record. If your supplier discharges untreated wastewater, your CSRD disclosure is inaccurate, your CSDDD due diligence is incomplete, and your buyer drops you. If your supplier's SMETA audit is expired by six weeks, the procurement system deselects you automatically — and the buyer does not ask why. The legal violation is the supplier's. The commercial and legal consequence is yours.

The regulatory frameworks that impose cascading liability — making a buyer legally responsible for what happens in their supply chain — are multiplying globally. The German Supply Chain Act (LkSG), the EU's CSDDD, the US Uyghur Forced Labor Prevention Act (UFLPA), the UK and Australian Modern Slavery Acts, the Canadian Fighting Against Forced Labour and Child Labour in Supply Chains Act — each of these creates a legal obligation for the buyer to know what is happening in their supply chain and to act on what they find. And each of them starts with the same operational question: what do you ask your suppliers — and what documentation do you demand — before you place the order?

Regulatory Obesity: The Compliance Burden No One Tracks

A single product sold globally — a Bluetooth speaker, a cotton t-shirt, a wooden chair — can now be subject to twenty or more regulatory frameworks before it reaches a customer. In the United States: FCC, UL, CPSC, Prop 65, TPPA, and state PFAS laws. In the European Union: CE Marking, RoHS, REACH, WEEE, GPSR, and CSDDD. In the United Kingdom: UKCA, UK REACH, and UK-specific safety regulations. In China: GB standards, CCC certification, and data security requirements. In Australia: RCM, modern slavery reporting, and packaging regulations. In the Middle East: Gulf Conformity Mark, Saudi SABER, UAE ECAS. In Africa: a growing patchwork of national standards and the emerging AfCFTA trade framework.

The technical term is regulatory obesity — and it is not limited to any one region. The number of rules a business must comply with has grown faster than the business's ability to discover, understand, and document compliance with them. The rules themselves are not the problem — product safety, environmental protection, worker rights, and supply chain transparency are legitimate policy objectives. The problem is that the rules do not coordinate across borders, they do not share data formats, and they do not come with a notification system.

Conflict Minerals (3TG) Compliance

Tin, tantalum, tungsten, and gold — collectively known as 3TG — are present in nearly every electronic product, from the solder on circuit boards to the capacitors in power supplies, from the tungsten vibration motors in smartphones to the gold contact pads in connectors.

But these four metals have a dark side. In certain regions — most notably the Democratic Republic of Congo (DRC) and adjoining countries — the extraction and trade of 3TG minerals has financed armed conflict, enabled forced labor, and caused severe human rights abuses. In response, legislators in the United States and the European Union have created mandatory supply chain due diligence regimes designed to break the link between mineral extraction and conflict financing.

If your product contains tin, tantalum, tungsten, or gold — and if your company is publicly traded in the US or imports these minerals into the EU — you have legal obligations to trace your supply chain, assess risks, and publicly report your findings.

Exporting to the EU: Surviving CBAM Penalties

If you operate a manufacturing, mining, or agricultural SME in South Africa—or anywhere else in the Global South—the European Union is likely one of your most valuable export markets. But the rules of trade have changed drastically. The EU’s Carbon Border Adjustment Mechanism (CBAM) places a literal price on the carbon emissions of your products.

While the tax is technically paid by the importer based in Europe, the regulatory burden falls squarely on you, the exporter. If you cannot provide precise carbon data, you will lose your EU buyers overnight.

EU Battery Regulation (2023/1542): Compliance Guide

The European Union has enacted the most comprehensive battery legislation in the world. Regulation (EU) 2023/1542, which entered into force in August 2023 and is now progressively applying its requirements, replaces the old Battery Directive (2006/66/EC) and fundamentally transforms how batteries are designed, manufactured, reported, and recycled.

This is not a narrow update. The new Battery Regulation introduces the world's first mandatory Battery Passport, imposes strict due diligence obligations on raw material sourcing, mandates carbon footprint declarations, sets binding recycled content targets, and significantly expands extended producer responsibility. If your product contains a battery — from the smallest consumer device to the largest industrial installation — these requirements affect you.

How to Verify a Supplier Certificate

Every manufacturer relies on supplier certificates. A Global Recycled Standard (GRS) certificate proves your recycled content. An FSC certificate validates your wood sourcing. An Oeko-Tex certificate confirms your textiles are free of harmful substances. An ISO 14001 certificate demonstrates your supplier's environmental management credentials.

But here is the uncomfortable truth: not every certificate your supplier sends you is genuine. Certificates can be expired, forged, altered, or simply issued to a different legal entity than the one selling you materials. If your compliance audit file contains a fraudulent certificate, the liability falls on you — not on the supplier who sent it. Market surveillance authorities, customs agencies, and retail buyers hold the importer or manufacturer responsible for verifying their supply chain evidence.

This guide shows you how to independently verify the authenticity of the most common supplier certificates, spot the red flags, and build an audit file that withstands scrutiny.