Skip to content
Compliance

Can I legally audit my Chinese supplier?

Yes, with real limits. Reviewing public registry records and visiting a supplier who has consented are lawful and normal. Covert investigation, data scraping, purchased personal data and undisclosed enquiries are not, and China has tightened enforcement around foreign-directed supply-chain investigation. Build the file from disclosable sources only.

Buyers are caught between two systems moving in opposite directions. Western regimes — forced-labour rules, corporate sustainability due diligence, customer audit programmes — require you to map, monitor and document your supply chain. Chinese law, meanwhile, has tightened around data, cross-border transfer and foreign-directed investigation. Both pressures are real, and the answer is not to pick a side but to work only in the space where both are satisfied.

MethodPosition
Reading the national company registryPublic information. Lawful and routine
Reading published court and enforcement recordsPublic. Lawful
Verifying a certificate with the issuing bodyLawful
Visiting a site with the supplier’s consentLawful. Get the consent in writing
Filming with the supplier’s consentLawful. Consent must be specific about what is filmed and where it goes
A structured questionnaire the supplier chooses to answerLawful. Their choice to answer is the point
Covert visits, pretext calls, undisclosed recordingDo not
Scraping databases, or buying personal dataDo not
Collecting workers’ personal informationDo not — sensitive personal information under PRC law
Where the line sits

Why a lawful file is a better file

This is the part buyers often miss. A dossier assembled through covert means cannot be shown to the regulator or customer who asked for it, because explaining how you obtained it creates a new problem. A file built entirely from registry records, verified certificates, consented site evidence and the supplier’s own documented answers is one you can hand over intact. The constraint produces the more useful product.

What a defensible file contains

  1. Corporate identity and structure, from the registry, with the source and retrieval date.
  2. Ownership and related entities, including former names.
  3. Site evidence — dated, geolocated where possible, with consent recorded.
  4. Certificates, each verified against the issuing body rather than accepted as a PDF.
  5. The supplier’s own written answers to a documented questionnaire, including what they declined to answer.
  6. A confidence grade against every finding: verified, consistent, or unverifiable.

That last item is what separates a due-diligence file from a marketing document. Recording that something could not be verified is more valuable than implying it was.

Want this done rather than explained?

A supplier dossier built to survive an audit — from US$690, 10–15 working days.

Compliance-Grade Supplier File

Sources

All sources checked 23 August 2026. This page is general information, not legal, tax or customs advice. Requirements vary by product, market and circumstance — confirm your own position before acting.

Have the version of this question that has your company in it?

Book a 45-minute consult. We map your situation to the right process, tell you honestly what is and is not possible, and give you a fixed fee. No obligation.

Book a consult · US$120 Credited in full against any service you go on to book.