A supplier emails you a PDF. Letterhead, an embossed-looking seal, a signature line, an ISO 22716 logo. They call the factory "GMP-certified" and "FDA-registered." You're days away from wiring a 30% deposit on a custom formulation order. The problem isn't whether the scan looks real. The problem is that a scan can be real and still prove nothing about the factory you're about to pay.
Ask for the certificate number, the issuing body, and the certification scope — then verify all three on the issuing body's own database. A PDF scan on its own can be expired, scope-limited, or issued to a different legal entity than the one you're contracting with.
This walkthrough covers what a sourcing manager needs before money moves: what each certification claim actually proves (and the gaps it leaves), five verification steps you can run yourself, and a copy-paste request template that asks a supplier for exactly the evidence that separates a real certificate from a decorative one.
What a Certificate Actually Proves — and What It Doesn't
Buyers tend to bundle three different things into one vague idea of "certified": a production quality management system, a third-party GMP audit, and a US regulatory registration. They are not the same, and a supplier who blurs them — intentionally or not — is not necessarily lying, but is handing you less than you think.
Key Takeaway: A GMP or ISO 22716 certificate proves an audit passed, at a point in time, for a defined scope. It does not prove ongoing compliance, product-line coverage, or that the certified entity is the one you're paying. "FDA registered" is self-submitted registration, not approval — and "FDA certified" is not a real status for cosmetics at all.
A Stamp on Paper Is Not a Production Floor
GMP, or Good Manufacturing Practice, is a quality management standard for how a factory runs — personnel hygiene, equipment maintenance, raw material control, batch records, deviation handling. ISO 22716 is the international cosmetic GMP standard: it defines the requirements, and an accredited third-party body audits the factory against them and issues a certificate if the audit passes.
Here is what that certificate actually documents. On the audit date, at the audited site, for the audited scope, the factory's systems met the standard. That is the full claim. It does not guarantee those conditions persist today. It does not certify every production line in the building. It does not transfer to a different company if the factory renames itself, restructures, or changes ownership. And it says nothing about whether your specific product — say, a pressed-powder color cosmetic — falls inside a scope originally audited for skincare emulsions.
Then there is "FDA," where buyers get tripped most often. Under MoCRA (the Modernization of Cosmetics Regulation Act), cosmetic facilities exporting to the US must register with the FDA and list their products. That registration is self-submitted by the facility. It is not an inspection, not an approval, and not a certification. The FDA does have inspection authority over cosmetic facilities, and MoCRA introduced adverse event reporting and safety substantiation requirements. But the FDA does not issue a "GMP certificate" for cosmetics. When a supplier says "FDA-certified" or "FDA-approved," that phrasing does not correspond to anything the FDA actually does for cosmetic products. Treat it as a signal that the supplier's compliance vocabulary is loose.
| Supplier claim | What it actually proves | What it doesn't prove | How to verify |
|---|---|---|---|
| "GMP certified" | An audit confirmed the factory's quality system met a GMP standard on the audit date | Ongoing compliance; that the scope covers your product; that the certificate is current | Ask which standard, the certificate number, issuing body, scope, and expiry |
| "ISO 22716 certified" | An accredited third party audited the factory against ISO 22716 cosmetic GMP | That the scope covers your product category and site; that the certificate is still valid | Verify the certificate number on the issuing body's or accreditation body's database |
| "FDA registered" | The facility submitted MoCRA facility registration and product listing to the FDA | FDA approval, inspection, or certification — none of which the FDA issues for cosmetics | Confirm the registration exists through the FDA registration lookup portal; ask for the registration number |
| "FDA approved" | Nothing, for cosmetics | The claim is not a real FDA status for cosmetic products | Treat as a red flag and ask the supplier to restate what they mean |
Here is how the pattern typically plays out when a buyer stops at the scan. A brand founder receives an ISO 22716 certificate scan, accepts it at face value, wires a deposit, and moves into formulation. Weeks later, a US retailer's vendor onboarding asks for the full audit report and the certified scope. The supplier resends the same scan. The scan's company name does not match the contract entity — the factory rebranded after a partnership split, and the old certificate was never reissued under the new name. The scope lists skincare, not the color cosmetics in the order. The buyer is mid-production with a deposit committed and no documentation that satisfies the retailer's compliance gate. The cost is not just the deposit. It is the lost launch window and a vendor relationship reworked under deadline pressure.
To be fair, when you are screening fifteen suppliers, a certificate scan is a reasonable first-pass filter. It tells you the factory has at least gone through some audit process, which is more than nothing. The mistake is not using the scan at the screening stage. The mistake is treating the scan as sufficient at the commitment stage. Screening answers whether to keep talking. Verification answers whether to pay.
Five Verification Steps Before You Pay a Deposit
These steps assume you have moved past screening and are evaluating one or two finalists. Run them before the deposit, not after.
-
Ask for the certificate number and the issuing body — not the scan. A real certificate carries a unique number and a named issuing body, often with an accreditation body behind it. Ask to see those fields clearly. If a supplier can only produce a scan and cannot state the number, the scope, or the expiry without flipping through files, that itself is information about how their documentation is managed.
-
Look up the certificate on the issuing body's own database. Many accredited certification bodies maintain public verification portals where a certificate number returns the holder name, scope, site address, and validity dates. If the issuing body offers no lookup, check the accreditation body's database. You can also check the issuing body's official website for a verification portal. Where no public verification exists, request a signed letter from the issuing body confirming the certificate's current status, and contact the body directly to confirm.
-
Check whether the certified entity name matches your contract entity. This is the step buyers skip most. A certificate issued to "Hangzhou XYZ Cosmetics Co., Ltd." does not cover orders placed with "XYZ Beauty Tech Co., Ltd.," even if the same person signs both. Company name changes, restructuring, and license-rental arrangements all break the chain. Match the legal entity on the certificate to the legal entity on your manufacturing agreement — exactly, character for character.
-
Confirm the scope covers your product category and the production site. ISO 22716 certificates carry a defined scope: product types and the physical site address that was audited. A factory certified for skincare at Site A is not certified for color cosmetics run at Site B, even inside the same company. Ask to see the scope page of the certificate, and check that your product type and the site where your goods will actually be produced are both listed.
-
Separate MoCRA registration from GMP claims — and flag "FDA approved." For US-bound products, ask for the MoCRA facility registration number and confirm the facility has registered and listed products. Treat "FDA approved" or "FDA-certified GMP" as a vocabulary red flag: ask the supplier to restate, in writing, what the FDA status actually is. A supplier who can cleanly distinguish "MoCRA-registered" from "ISO 22716-certified" from "third-party GMP-audited" understands their own compliance. One who lumps them all into "FDA-certified" may not.
Key Takeaway: The five checks reduce to one rule — verify the certificate against an independent source (the issuing body's database, the contract entity, the scope page), not against the supplier's own PDF.

The Certificate Request Template Buyers Can Send Today
Here is a message you can adapt and send to a supplier before you commit a deposit. It asks for the specific evidence that makes independent verification possible — not a scan, but the fields that let you check on your own.
Key Takeaway: A written request template forces suppliers to disclose verifiable details — certificate number, issuing body, scope, and expiry — instead of waving a PDF.
Subject: Documentation request — certification verification for [Your Brand / Project Name]
Hi [Supplier contact],
Before we move to contract and deposit, we need to verify your facility's certifications independently. Please provide the following for each claim (GMP / ISO 22716 / FDA / MoCRA):
- Certificate or registration number
- Full name of the issuing body (and accreditation body, if applicable)
- Certification scope — product categories covered
- Certified site address (the physical production location audited)
- Issue date and expiry date
- Whether the certificate is verifiable on the issuing body's public database, and the lookup method
- The legal entity name as it appears on the certificate
- For US-market orders: MoCRA facility registration number and product listing confirmation
Please also share the most recent GMP audit report (not just the certificate page) and confirm whether the certified entity name matches the entity that will appear on our manufacturing agreement.
Thanks, [Your name]
A supplier who responds with complete, specific answers — numbers, named bodies, scope pages, expiry dates — is one you can verify. A supplier who resends the same scan and says "it's all on there" is one you cannot. The difference matters most when a retailer, a marketplace, or a regulator later asks you to prove your supply chain, and you need documentation that holds up beyond a decorative PDF.
If you are evaluating suppliers for a private label or custom formulation project and want to know what your target market — US, EU, Canada, Australia, or a combination — actually requires before you commit a deposit, request a certification verification packet. We will send the documentation checklist mapped to your product category and target market, and walk through which certificates your project genuinely needs versus which are nice-to-have. Bring your product type, packaging direction, and launch market, and we will tell you where the real compliance gaps sit.