Can I legally audit my Chinese supplier?
Yes, with real limits. Reviewing public registry records and visiting a supplier who has consented are lawful and normal. Covert investigation, data scraping, purchased personal data and undisclosed enquiries are not, and China has tightened enforcement around foreign-directed supply-chain investigation. Build the file from disclosable sources only.
Buyers are caught between two systems moving in opposite directions. Western regimes — forced-labour rules, corporate sustainability due diligence, customer audit programmes — require you to map, monitor and document your supply chain. Chinese law, meanwhile, has tightened around data, cross-border transfer and foreign-directed investigation. Both pressures are real, and the answer is not to pick a side but to work only in the space where both are satisfied.
| Method | Position |
|---|---|
| Reading the national company registry | Public information. Lawful and routine |
| Reading published court and enforcement records | Public. Lawful |
| Verifying a certificate with the issuing body | Lawful |
| Visiting a site with the supplier’s consent | Lawful. Get the consent in writing |
| Filming with the supplier’s consent | Lawful. Consent must be specific about what is filmed and where it goes |
| A structured questionnaire the supplier chooses to answer | Lawful. Their choice to answer is the point |
| Covert visits, pretext calls, undisclosed recording | Do not |
| Scraping databases, or buying personal data | Do not |
| Collecting workers’ personal information | Do not — sensitive personal information under PRC law |
Why a lawful file is a better file
This is the part buyers often miss. A dossier assembled through covert means cannot be shown to the regulator or customer who asked for it, because explaining how you obtained it creates a new problem. A file built entirely from registry records, verified certificates, consented site evidence and the supplier’s own documented answers is one you can hand over intact. The constraint produces the more useful product.
What a defensible file contains
- Corporate identity and structure, from the registry, with the source and retrieval date.
- Ownership and related entities, including former names.
- Site evidence — dated, geolocated where possible, with consent recorded.
- Certificates, each verified against the issuing body rather than accepted as a PDF.
- The supplier’s own written answers to a documented questionnaire, including what they declined to answer.
- A confidence grade against every finding: verified, consistent, or unverifiable.
That last item is what separates a due-diligence file from a marketing document. Recording that something could not be verified is more valuable than implying it was.
Want this done rather than explained?
A supplier dossier built to survive an audit — from US$690, 10–15 working days.
Sources
- National Enterprise Credit Information Publicity System (国家企业信用信息公示系统)
- Personal Information Protection Law of the PRC
- European Commission — Forced labour regulation
All sources checked 23 August 2026. This page is general information, not legal, tax or customs advice. Requirements vary by product, market and circumstance — confirm your own position before acting.
