Skip to content

Supply Chain

Conflict Minerals: Automate 3TG Due Diligence

Conflict minerals regulations in both the US (Dodd-Frank Section 1502) and the EU (Regulation 2017/821) require companies to trace the sourcing of tin, tantalum, tungsten, and gold (3TG) through their supply chains, conduct due diligence, and file compliant disclosures. With supply chains spanning multiple tiers and continents, manual CMRT collection and verification is error-prone and resource-intensive.

Conflict minerals software automates the collection of Conflict Minerals Reporting Templates (CMRTs), conducts reasonable country of origin inquiries (RCOI), and generates compliant disclosures for SEC and EU filing.

Conflict Minerals (3TG) Compliance

Tin, tantalum, tungsten, and gold — collectively known as 3TG — are present in nearly every electronic product, from the solder on circuit boards to the capacitors in power supplies, from the tungsten vibration motors in smartphones to the gold contact pads in connectors.

But these four metals have a dark side. In certain regions — most notably the Democratic Republic of Congo (DRC) and adjoining countries — the extraction and trade of 3TG minerals has financed armed conflict, enabled forced labor, and caused severe human rights abuses. In response, legislators in the United States and the European Union have created mandatory supply chain due diligence regimes designed to break the link between mineral extraction and conflict financing.

If your product contains tin, tantalum, tungsten, or gold — and if your company is publicly traded in the US or imports these minerals into the EU — you have legal obligations to trace your supply chain, assess risks, and publicly report your findings.

How to Verify a Supplier Certificate

Every manufacturer relies on supplier certificates. A Global Recycled Standard (GRS) certificate proves your recycled content. An FSC certificate validates your wood sourcing. An Oeko-Tex certificate confirms your textiles are free of harmful substances. An ISO 14001 certificate demonstrates your supplier's environmental management credentials.

But here is the uncomfortable truth: not every certificate your supplier sends you is genuine. Certificates can be expired, forged, altered, or simply issued to a different legal entity than the one selling you materials. If your compliance audit file contains a fraudulent certificate, the liability falls on you — not on the supplier who sent it. Market surveillance authorities, customs agencies, and retail buyers hold the importer or manufacturer responsible for verifying their supply chain evidence.

This guide shows you how to independently verify the authenticity of the most common supplier certificates, spot the red flags, and build an audit file that withstands scrutiny.

How to Share an ISO 14001 Certificate

Your company earned ISO 14001 certification. The audit was rigorous. The environmental management system is real. The certificate is valid.

Now every customer, every buyer, and every procurement questionnaire asks you to prove it. And every time, you email the same PDF.

The certificate lives in a folder on your shared drive. It gets attached to emails, forwarded to procurement teams, uploaded to supplier portals, printed for the office wall. Somewhere along the way, someone forwards an expired version. Someone else asks "is this the current one?" Someone prints it and pins it to a corkboard where it fades in the sun.

This is not how a world-class certification should be shared. Here's how to fix it.

EUDR Compliance: Due Diligence & Key Deadlines

In 2025, Dutch authorities conducted pilot inspections across 20 operators and found widespread shortcomings in due diligence documentation. Dry runs led by German, Belgian, Dutch, and French regulators confirmed that authorities expect a complete "paper trail" for each specific shipment — not just a general due diligence system on paper. Rotterdam, Europe's largest port, is now a regulatory checkpoint where shipments without verified geolocation data can be stopped.

A cocoa importer we onboarded last quarter had their entire shipment flagged at Rotterdam port. The problem wasn't that their supply chain was deforestation-linked — it was that they couldn't produce the geolocation data fast enough. On the Sustalium platform, we see this pattern repeat across commodities: the legal burden is on the importer, not the supplier.

The EU Deforestation Regulation (EUDR — Regulation [EU] 2023/1115) is now fully enforced. Unlike voluntary sustainability pledges, it makes it a criminal offense to import commodities produced on land deforested or degraded after December 31, 2020. The burden of proof is entirely on your business.

How B2B Buyers Verify Supplier Compliance

Ask any procurement manager how they verify supplier compliance today, and the answer is the same across every industry: "We email them and ask for their certificates."

Then the waiting begins. The supplier finds the PDF — hopefully the current version. They email it. The buyer files it in a shared drive, or a SharePoint folder, or their inbox. Six months later, when an auditor asks for proof of supplier compliance, someone searches for the attachment. It may have the wrong date, the wrong version, or both. So they email the supplier again.

This is not a process. It is a ritual — one that every procurement team performs and that every audit exposes as insufficient.

Beyond the PDF: EU DPP Requires Structured Data

For years, the EU Digital Product Passport (DPP) has been discussed as a futuristic, abstract concept under the Ecodesign for Sustainable Products Regulation (ESPR). As we navigate mid-2026, the theory has violently collided with reality.

With the mandatory EU Battery Passport taking effect in February 2027, manufacturers and importers are currently in a mad dash to collect, format, and host their supply chain data. If you are still relying on shared folders full of PDFs and Excel spreadsheets to manage your compliance, you are on a collision course with EU Customs.

RoHS vs. REACH: Supplier Requirements

One of the most common causes of supply chain friction in European manufacturing is the conflation of REACH and RoHS.

It happens every day: A procurement manager emails a supplier asking for a "REACH/RoHS Certificate." The supplier, based outside the EU and confused by the acronyms, replies with a generic letter stating their product is "safe and compliant." The procurement manager files it away. A year later, a market surveillance authority audits the manufacturer, deems the generic letter invalid, and forces a product recall.

While both REACH and RoHS are European regulations designed to protect human health and the environment from hazardous chemicals, their scopes, thresholds, and reporting mechanics are completely different. To secure your supply chain, you must know exactly what to ask for.

PFAS-Free Declarations for Retail Buyers

If you supply consumer goods, apparel, cosmetics, or electronics to major retailers or online marketplaces, you have likely received a sudden, urgent request for a PFAS-Free Declaration.

Per- and polyfluoroalkyl substances (PFAS)—commonly dubbed "forever chemicals" due to their extreme persistence in the human body and environment—are facing an unprecedented wave of global regulation. In the United States, several states (including California, Maine, and Vermont) have enacted strict bans on intentionally added PFAS in consumer products.

Meanwhile, the European Union is evaluating a blanket restriction under REACH.

To protect themselves from immense liability and potential class-action lawsuits, retail giants (such as Amazon, Target, and Costco) are enforcing strict "flow-down" policies. If you cannot provide a valid, verifiable chemical compliance statement proving your products contain no intentionally added PFAS, your inventory will be immediately rejected and your vendor status terminated.

Here is how to audit your supply chain and draft a legally compliant PFAS-free declaration.

How to Write a Modern Slavery Statement

If you supply physical goods, raw materials, or components to large corporate buyers, you are no longer evaluated solely on price and quality. In the modern regulatory landscape, corporate buyers must prove their supply chains are clean of human rights abuses.

Under laws like the UK Modern Slavery Act 2015, the Australian Modern Slavery Act 2018, and Canada's newer Bill S-211, large enterprises must publish annual public statements detailing how they prevent forced labor, child labor, and human trafficking in their global supply networks.

Because your small-to-medium enterprise (SME) is part of their supply chain, their compliance depends entirely on your data.

Even if your business is well below the legal revenue thresholds that mandate filing your own statement, you will still receive urgent requests from your buyers demanding a signed Modern Slavery Statement or an Ethical Labor Declaration.

If you cannot provide this document, you represent a compliance risk. To protect their business, corporate buyers will terminate your vendor status and switch to a compliant competitor. Here is how to draft a legally robust, audit-ready declaration.