Quality assurance engineer conducting a manufacturing compliance inspection.
28 Jul 2026

In mature compliance programs and quality management systems, testing everything simply isn’t practical or defensible.

Regulators aren’t looking for blanket testing anymore; instead, they expect a thoughtful, risk-based testing approach that is aligned with applicable legislation and regulations such as RoHS- 2011/65/EU, REACH-Regulation (EC) No 1907/2006, POP’s -Regulation (EU) 2019/1021 and the new PPWR - Regulation (EU) 2025/40 for starters. In other words, the focus is on demonstrating due diligence, not running unnecessary tests.

When companies consider risk-based testing for restricted substances, their approach should be straightforward: to utilize  testing when a productor or material poses real uncertainty or risk, but rely on robust  technical documentation when compliance concerns are low.

Building a Defensible Testing Decision Matrix

A strong compliance program starts with structure. In general, this structure comes in the form of a decision matrix, a decision tree, or another defined process that translates regulatory expectations into consistent, repeatable decisions.

At its core, the method should answer the two following questions:

  • How likely is it that restricted substances are present? and
  • How strong is the existing compliance data?

To ensure testing answers these questions, companies should consider several key inputs about their product:

  • Material Type
    Some materials carry more inherent risk. For instance, polyvinyl chloride, solders, pigments, and coatings are more likely to contain restricted substances like lead, cadmium, or phthalates. Higher inherent risk means higher need for testing.
  • Supplier Maturity
    Companies should evaluate their suppliers’ processes. Established suppliers with appropriately audited systems and detailed material disclosure information significantly reduce uncertainty.
  • Data Completeness
    Full Material Declarations (FMDs)—for example, IPC-1752A Class D—are more reliable to regulators than partial or generic statements However, FMDs can be difficult to obtain for certain materials commonly used in complex products, such as electronic components, adhesives, coatings, inks, elastomers, and proprietary alloys. These materials often involve complex supply chains, proprietary formulations, or confidential business information that suppliers are unwilling or unable to disclose at the substance level. As a result, manufacturers may need to supplement available documentation with risk assessments or targeted analytical testing to demonstrate compliance.
  • Part Complexity
    The more complex the product’s assembly, the greater the chance that a non-compliant product or material slips through. Therefore, products with complex material make up are more likely to require testing.
  • Regulatory History
    If a component or material type has a history of exemptions or violations, it deserves extra scrutiny. This is especially relevant to compliance with California Proposition 65.

A streamlined way to think about risk-based testing is to categorize products as low, medium, or high risk. These categories are detailed in the table below. While not every product will fit cleanly within the parameters of one category, this framework simplifies product analysis to identify compliance gaps.

Risk Category Supplier Status Data Availability Material Composition Testing Needs
Low Trusted supplier with mature compliance program Complete data Low-risk materials used No testing needed (unless required by legislation or by the company's client). Companies can rely on technical documentation.
Medium Supplier does not have a fully mature compliance program Some gaps in data Moderate-risk materials used Targeted screening is needed (e.g., X-ray fluorescence).
High Unknown supplier/supplier with previous compliance issues and or no or ineffective compliance program Incomplete data High-risk materials Full analytical testing is required (e.g., inductively coupled plasma optical emission spectroscopy, gas chromatography-mass spectrometry).


A product’s material supplier is an important factor when considering whether risk‑based testing is necessary because not all suppliers demonstrate the same level of capability, maturity, or compliance performance. Even if a supplier meets all the requirements to make it onto a company’s approved vendor or supplier list, they should still exhibit qualities that demonstrate their maturity and trustworthiness, specifically for restricted substances. Some examples of this would be:

  • Transparency
    • Suppliers/Vendors provided complete compliance documentation (g., certificates of conformity, FMDs, Safety Data Sheets, etc.).
    • Suppliers/Vendors have clear traceability to their raw materials.
  • Documentation
    • Suppliers/Vendors maintain documented processes to identify, track, and communicate restricted substances throughout their supply chain.
  • Communication
    • Suppliers/Vendors update their material’s compliance status when regulations change, without repeated requests.
  • Verification Practices
    • Suppliers/Vendors hold a third‑party compliance certification (g., ISO 9001, etc.).
    • Suppliers/Vendors know what’s in their products and don’t rely on testing or certificates to determine compliance. They trust but verify!

Even trusted suppliers should still be validated periodically.

Testing Strategy: When It’s Actually Required

From a regulatory standpoint, the key concern isn’t whether a company tested, but whether their testing approach reasonably assures compliance with the legislation and restrictions.

Testing should never be routine—it should be triggered. Common triggers include:

  • Onboarding a new supplier or using a new material;
  • Driven by Regulatory updates (e.g., additions to the Restriction of Hazardous Substances [RoHS] directive, new Substances of Very High Concern) or new regulations (e.g., the Packaging and Packaging Waste Regulation);
  • Inconsistencies in supplier data;
  • Known ongoing high-risk applications (e.g., cables, elastomers, solders).
  • Market surveillance findings.

What matters most is that a testing program clearly explains why testing was or wasn’t performed. In many cases, that justification carries more weight than the test results themselves. Testing provides evidence of compliance only for the specific sample tested at a particular point in time—it is a snapshot in time. Because materials, formulations, manufacturing processes, and suppliers can change, testing alone cannot ensure ongoing compliance. A robust restricted substances program combines risk-based testing with supplier due diligence, material declarations, change management, and documented compliance assessments to provide confidence that products remain compliant throughout their lifecycle.

Retiring Legacy Test Data Without Creating Risk

Older, “legacy” test data for restricted substances can quietly become a liability if they’re not managed properly. Many compliance issues don’t come from missing data, but from relying on outdated or irrelevant data.

Reasons data might become legacy include:

  • Testing doesn’t align with current substance lists and limits;
  • Material or supplier changes since the test was conducted;
  • Poor sample representativeness;
  • Outdated methods or insufficient detection limits; and
  • Lack of traceability to why testing was executed initially.

The following four steps provide a practical approach to avoid regulatory compliance issues as data becomes outdated.

Step 1: Define Validity Criteria

  • Set an age threshold for when data should be reviewed (e.g., anything older than three to five years).
  • Confirm the data’s alignment with current regulations.
  • Ensure there is traceability to the current Bill of Materials (BOM) and materials used and consumed during production. This can be difficult depending on BOM management and also for “relabeled” products.

Step 2: Reassess Risk

  • Re-map components into your current risk matrix or decision tree.
  • Reduce confidence where traceability or data completeness is weak.

Step 3: Replace Strategically

  • High risk → Re-test the product immediately.
  • Medium risk → Supplement your existing data with targeted screening or updated supplier data.
  • Low risk → Retain the data but document your justification.

Step 4: Document Everything:

  • Regulators will accept legacy data, but only if you can justify its continued use through change control records, supplier revalidation, and evidence of material consistency.

What Regulators Actually Expect

Across the European Union (EU) and other major regulatory jurisdictions market surveillance authorities tend to focus on three core areas: technical documentation (i.e., aligned with EN IEC 63000; this guidance is extremely valuable and should be utilized even if the product is not required to be RoHS‑compliant and/or is not being placed on the market in the EU), supply chain due diligence, and risk‑based justification of testing decisions.

These authorities are not auditing or focusing on the volume of testing, they are evaluating the quality of a company’s decision-making. The testing volume should be relevant to the quality and risk of the products placed on the market. Testing is also verification that a company’s restricted substance compliance and quality management systems are functioning as intended.

A company that tests everything without a clear rationale can appear less compliant than one that tests selectively with strong justification.

Key Takeaways

A well-executed risk-based compliance testing framework strengthens your compliance position and aligns with how regulators assess conformity. The objective isn’t to eliminate testing, but to ensure every test you perform is necessary, justified, and defensible.

Remember the key takeaways:

  • Testing is a tool, not always a requirement. Use it where risk justifies it.
  • A decision matrix or tree brings consistency and strengthens audit defensibility.
  • Legacy compliance data needs active management, not passive reliance.
  • Clear documentation and testing justification are just as important as data.

If you're looking to build or refine a risk-based compliance testing framework, Intertek Assuris can help you develop practical, defensible strategies that support regulatory compliance while optimizing your testing program. Contact our experts to learn more.

Headshot of Robert (Bob) Trimble
Robert (Bob) Trimble

Program Manager – Global Restricted Substances (GRS), Intertek Assuris

Bob is a subject matter expert in the global restricted substances (RoHS, REACH, Prop 65, etc.) space with more than 15 years of experience servicing organizations of all sizes. In his vast experience, Bob has helped hundreds of companies address compliance with a focus on implementing compliance assurance systems aligned with how customers produce products and manage business. Bob’s 20 years of manufacturing experience allows him to understand and adapt to different manufacturing and business practices to ensure that the compliance systems are effective and efficient based on the customers business model.