A New Chapter: Compliance & Risks is now Adherent. Read more.

16 min read
Blogs

The Practice of Product Compliance: A Complete Operating Model

Adherent (formerly Compliance & Risks). Professionals in office setting - discussing compliance trends August 2024

This blog was originally posted on 1st October, 2026. Further regulatory developments may have occurred after publication. To keep up-to-date with the latest compliance news, sign up to our newsletter.

THIS BLOG WAS WRITTEN BY THE ADHERENT MARKETING TEAM TO INFORM AND ENGAGE. HOWEVER, COMPLEX REGULATORY QUESTIONS REQUIRE SPECIALIST KNOWLEDGE. TO GET ACCURATE, EXPERT ANSWERS, PLEASE CLICK ASK AN EXPERT.


Product compliance is the practice of determining which regulations apply to a product in each market it is sold in, translating those regulations into design and documentation requirements, and holding evidence that the requirements are met. It runs as four phases and nineteen steps: Understand your obligations, Decide what to commit to, Execute through design and manufacturing, and Sustain the practice against regulatory change. Most teams run it as reactive casework instead, which is why they cannot say which steps they perform deliberately, which they perform by accident, and which are missing entirely.

  • Product compliance is a discipline, not a task queue. It can be described as four phases covering nineteen distinct steps, each with an owner, an input, and an output another step consumes.
  • Phase one is building your regulatory universe and translating regulations into product-level requirements. No control or evidence work should start before it.
  • Phase two is a decision phase, not an administrative one. Teams choose a compliance level, cost it, and get named leadership agreement on the trade-offs.
  • Execution lives in design, manufacturing, and evidence, which means product, engineering, and quality own steps compliance cannot perform alone.
  • Mature practices differ from reactive ones on three markers: obligations are mapped to individual products, evidence exists before anyone asks for it, and regulatory change arrives as a monitored input rather than a surprise.
  • Most teams should start by mapping their regulatory universe against their actual product and market list, because every downstream step inherits that gap.

Product compliance is the practice of determining which regulations apply to a product in each market it is sold in, translating them into design and documentation requirements, and holding evidence that those requirements are met. It needs defining because most organizations run it as reactive casework, with no named steps, no owner for applicability decisions, and no maturity baseline to improve against.

It is worth separating from its neighbours. Corporate compliance covers ethics, anti-bribery, and conduct. Quality management covers whether the product meets its own specification. Environmental health and safety covers the workplace. Product compliance covers whether the product itself is legal to place on a given market, and whether you can prove it.

The scope has widened considerably. A single physical product can now attract obligations across chemicals restrictions, product safety, labeling and ecolabeling, energy efficiency, circular economy and packaging rules, extended producer responsibility schemes, cybersecurity and AI requirements, sustainability disclosure, and market-access registration. Adherent’s own figures put the average at 1,002 regulations for a new product entering a single market.

Undefined practices fail in predictable ways. Nobody signs the applicability decision, so it is made implicitly by whoever noticed the regulation. Evidence gets assembled retroactively under deadline pressure. Change monitoring happens by inbox. Compliance and product use different vocabulary for the same requirement, so requirements arrive late and are treated as interruptions rather than as ordinary product requirements.

The cost of that state shows up as launch delays, blocked shipments, recalls, retailer de-listing, and restated sustainability claims. In Thrv Research’s State of the Industry Report, drawn from more than 500 respondents, 69% of compliance leaders said remediating product compliance issues is difficult or very difficult. Naming the practice buys you four things a reactive team does not have: repeatability, delegability, auditability, and a language leadership can actually fund.

If it is a practice, it has phases. The rest of this guide is the model.

The operating model has four phases. Understand means knowing your obligations. Decide means choosing and funding a compliance level. Execute means building compliance into design, manufacturing, and evidence. Sustain means absorbing regulatory change and proving the practice pays. Nineteen discrete steps sit inside those phases, each with an owner, an input, and an output that another step consumes.

Each phase has an exit criterion, which is what must be true before the next phase can start.

Phase 1, Understand. Exit criterion: you can name every regulation that applies to a given product in a given market, and what proof each one demands.

  1. Identify which markets are worth entering, and what each one costs to comply with
  2. Build your regulatory universe across regulations, standards, and internal policy
  3. Translate regulations into testable product requirements with dates attached
  4. Define what counts as proof before the compliance work starts

Phase 2, Decide and align. Exit criterion: a named leader has agreed a compliance level per market, and it is funded.

  1. Resource it honestly, covering process change, cost, time, and people
  2. Treat the compliance level as an ROI decision rather than a default
  3. Build the business case and get leadership agreement
  4. Align product teams on compliance-driven change and the trade-offs it forces
  5. Make the requirements understandable to every department that has to act on them

Phase 3, Execute and maintain. Exit criterion: the requirement is built into the product, held in production, and documented as the work happens.

  1. Design for compliance across the product lifecycle
  2. Hold the line in manufacturing, including supplier adherence and controls
  3. Be audit-ready by default rather than assembling evidence on request
  4. Prove compliance to internal stakeholders in language they can use
  5. Pass the external test with auditors, customers, and customs
  6. Remediate properly when compliance breaks

Phase 4, Stay ahead and prove value. Exit criterion: change is a monitored input with an owner, and compliance reports against business goals.

  1. Stay ahead of regulatory change before it lands
  2. Turn regulatory change into a board-ready briefing
  3. Reassess whether each market is still worth maintaining
  4. Report the impact of compliance on business goals

Two properties of the model matter. Steps are sequential the first time and continuous afterwards. And the model is descriptive, not certifiable: no ISO standard defines it, which is exactly why most teams have no baseline to measure against.

You build a regulatory universe. Every market you sell into, crossed against every product family, mapped to the regulations that apply and the specific requirements each one imposes. Then you define what proof each requirement demands. Without that grid, everything downstream is guesswork dressed as diligence.

Market scoping comes first, because entry cost is partly a compliance cost and belongs in the decision before you inventory a market’s rules.

The universe itself has a source hierarchy: regulations, directives, harmonised standards, national transpositions, and state or provincial rules. The common trap is monitoring only the headline regulation and missing the transposition that actually binds you. Regulatory intelligence is the discipline that keeps this current, and a regulatory crosswalk is how teams stop treating overlapping frameworks as unrelated projects.

Applicability assessment is where most teams lose accuracy. Obligations are triggered by product attributes: chemistry, energy use, connectivity, packaging, and the claims made on the label. Mapping at SKU level beats assuming at category level, because the exception is usually a single variant.

Requirement translation converts legal text into something a design engineer can act on: testable, assignable, dated. Evidence definition happens at the same moment, not later. Deciding what counts as proof after the product is built is how teams end up reconstructing rather than documenting.

The most common blind spots are consistent. A universe that covers EU and US federal rules but misses US state chemical restrictions, extended producer responsibility schemes, and emerging-market registration requirements. Adherent’s state-level PFAS snapshot exists because that particular gap is so widespread.

This is also where the economics change. Adherent tracks an average of 217 regulatory changes per month globally, and 27 per month in the US for a typical product category. Continuous monitoring and SKU-level applicability across that volume is the part humans cannot scale by hand, which is why agentic AI is aimed at these two steps specifically.

Compliance level is a business decision, and there is more than one defensible answer. Legal minimum. A deliberate buffer above the minimum that anticipates pipeline rules. Voluntary or ecolabel positioning that goes further for commercial reasons. Or deliberate non-entry into a market. Decide it explicitly, cost it, and get named leadership agreement, because the level dictates resourcing, roadmap changes, and which markets stay open. An undecided level is the most common reason compliance programmes stall halfway.

Resourcing honestly means counting more than headcount. It includes external testing, tooling, and the internal cost carried by engineering and supply chain time, which is the part that never appears in a compliance budget.

The ROI framing is what makes the decision legible to a CFO: revenue protected per market, cost of failure through recall, penalty, or de-listing, and cost of delay to launch. The real cost of non-compliance sets out how market-access risk compounds over time, and why the framing works better than an obligation list.

Two alignment steps follow the decision. Product teams need compliance change to arrive as ordinary product requirements with dates, not as escalations. And every department that has to act needs the requirements in language it can use, which usually means one shared requirement vocabulary across legal, engineering, procurement, and marketing claims.

The artifact to produce is small and unusually valuable: a one-page compliance level statement per market and product family, signed.

Execution means the requirement is built into the product, held in production, and documented as the work happens. That runs across four moments, with a defined path for when something fails.

Design is where compliance is cheapest. Requirement gates at concept, detailed design, and pre-launch, with substance and material choices treated as compliance decisions rather than engineering ones.

Manufacturing is where designed-in compliance meets the supply chain. Supplier change control, substitution risk, incoming material verification, and contract manufacturer obligations are the controls that hold the line, and traceability systems are what make the claim provable afterwards.

Evidence should be captured at the moment of work, with version, date, and owner attached. Evidence assembled for an audit is not evidence, it is reconstruction. Building an audit-ready evidence system covers what that looks like in practice. It matters because 62% of compliance leaders in the same Thrv Research study said they struggle to provide evidence of compliance to external stakeholders.

Proving compliance runs internally first, through self-assessment and technical file completeness, then externally to notified bodies, accredited labs, retailer and customer audits, and customs or market-surveillance requests. The rule for external evidence is to provide the right amount, no more and no less, because over-sharing creates its own exposure.

Remediation needs a defined sequence: contain, determine scope, meet notification duties, take corrective action, and feed root cause back into design. Deciding between recall, rework, and withdrawal should follow root cause, not precede it.

Execute fails hardest when Understand was skipped. Teams then control for the wrong requirement, precisely and thoroughly.

Sustaining the practice means treating regulatory change as a monitored input with an owner and a triage rule, escalating material changes in business language, periodically re-testing whether each market is still worth serving, and reporting compliance performance as measurable value rather than activity.

Monitoring separates horizon scanning from in-force tracking, and triages by product impact rather than by how important the regulation looks. Compliance monitoring is the operational version of this, and regulatory forecasting is what turns alerts into lead time.

A board-ready briefing translates a regulatory development into four things: revenue at risk, deadline, decision needed, and owner. Anything longer gets read as background.

Market re-evaluation is the step almost nobody documents. As compliance cost rises, staying is a recurring decision that deserves re-underwriting, and exit is a legitimate recommendation.

Proving the practice pays means reporting against goals leadership already tracks: launch delays avoided, first-pass audit rate, evidence completeness, time to market access, and incidents avoided. Adherent’s own benchmark for the speed difference is stark. Assessing 200 key regulations manually with a general-purpose LLM takes four to six months. With C2P, six to eight weeks. On the Adherent platform, under ten minutes.

Change data then updates the regulatory universe, which closes the model back to phase one.

Three markers. Mature practices map obligations to individual products before launch. They hold evidence before anyone asks for it. And they receive regulatory change as a routine monitored input. Reactive practices discover obligations from customers, auditors, or authorities, and assemble proof under deadline pressure.

A four-level ladder is enough to place a team honestly.

  • Reactive. Obligations surface from outside. Evidence is reconstructed. One expert holds the practice in their head.
  • Documented. Steps are written down and a named owner exists, but execution still depends on individuals remembering to follow them.
  • Managed. Obligations are mapped to products, evidence is captured at the point of work, and change has a triage rule.
  • Anticipatory. Pipeline regulation informs design decisions before it is in force, and market decisions are re-underwritten on a cycle.

For a faster read, mark each of the nineteen steps as absent, ad hoc, owned, or automated. Three diagnostic questions expose real maturity quickly. Who signs the applicability decision? How long would it take to produce a full technical file for one SKU? What percentage of your product range is actually mapped?

The anti-patterns are consistent: the spreadsheet of record, the single expert who is the practice, and compliance sign-off as a launch-day rubber stamp.

Start with phase one, step two: build the regulatory universe for the products and markets you already sell in. Every later step inherits gaps in that grid, which makes it the highest-leverage first move. A first usable version takes weeks, not quarters.

A workable ninety-day sequence:

  1. Inventory products and markets as they actually are, not as the catalogue describes them
  2. Build the regulatory universe for your top revenue markets first
  3. Translate requirements for one product family end to end
  4. Produce an evidence gap list from that family
  5. Take a resourcing and compliance level decision to leadership

Scope by revenue at risk rather than by ease. The product family that is simplest to map is rarely the one exposing you.

Four artifacts are worth producing: the product and market grid, the requirement register, the evidence gap list, and the signed compliance level statement. Involve regulatory, product and engineering, quality, procurement, legal, and marketing claims from the first week. Defer full automation, the wider ESG reporting build, and remediation playbooks deliberately.

Never work on a compliance step whose upstream step is missing. A control without a mapped requirement, or evidence without a defined proof standard, will not hold. Map your regulatory universe against your real product and market list first, then work forward. For where sustainability obligations fit against this model, the 2026 survival guide to sustainability product compliance covers the disclosure side in more depth.

  • Who owns product compliance in a manufacturer?
    Usually a regulatory affairs or product compliance function owns the practice, but not every step. Design, manufacturing, and evidence capture are owned by product, engineering, and quality. The step compliance must own outright is the applicability decision, because it determines what everyone else is working to.
  • How is product compliance different from quality management?
    Quality management asks whether the product meets its own specification. Product compliance asks whether the product is legal to place on a given market, and whether you can prove it. A product can be perfectly built to spec and still be non-compliant.
  • How long does it take to map a regulatory universe?
    For a defined set of products in a small number of markets, a first usable version takes weeks. Doing it across a full catalogue and every market by hand is where teams stall, because the maintenance load exceeds the build.
  • Do we need a platform, or can we run this in spreadsheets?
    Phases two and three can be run manually by a disciplined team. Phases one and four are where manual effort breaks down, because continuous monitoring and SKU-level applicability across hundreds of monthly changes is not a spreadsheet problem.
  • What should we measure to show the practice is working?
    Report against goals leadership already tracks: launch delays avoided, first-pass audit rate, evidence completeness, time to market access, and incidents avoided. Activity metrics like alerts reviewed do not survive a budget conversation.

See Adherent in Action

Discover how agentic AI is reshaping product compliance for global enterprises.

An open and a closed digital playbook titled "The Ultimate Product Compliance Playbook" on a dark background, with a download icon.

The Ultimate Product Compliance Playbook

What the World’s Leading Product Organizations Have Figured Out About Product Compliance