Building a Compliance Program That Scales From 10 SKUs to 10,000
The process that works for a ten-product startup breaks quietly at a thousand SKUs. Here's what actually needs to change, and what doesn't.
At ten SKUs, a compliance program can survive on good intentions. One person tracks supplier declarations in a spreadsheet, checks each new product by hand, and generally knows the state of things without needing a system to tell them. At a thousand SKUs, that same approach doesn't fail loudly — it fails quietly, one missed re-verification and one untracked supplier substitution at a time.
What breaks first
Tribal knowledge. The person who "just knows" which products rely on which exemptions becomes a single point of failure the moment they're on leave, or leave the company.
Manual re-verification. A yearly review cycle that took an afternoon at ten SKUs takes weeks at a thousand — and gets quietly deprioritized when it does, which is exactly when declarations go stale.
Undifferentiated effort. Spreading equal scrutiny across every SKU means high-risk components (solder, platings, PVC cabling, anything from a region with less mature substance-control infrastructure) get the same light-touch review as a pre-certified branded connector with a strong declaration history — which is both less safe and less efficient.
What has to change with scale
- Risk-based allocation, not uniform effort. Testing budget and supplier audit time should track actual risk profile, not be spread evenly across the portfolio.
- Structured data over institutional memory. A declaration and its status need to be queryable, not dependent on someone remembering which supplier email had the answer.
- Change-triggered review, not purely calendar-triggered review. A supplier substitution or BOM revision should automatically reopen the compliance question for that specific part, regardless of where it falls in the annual cycle.
- Clear, singular ownership — someone with actual authority to hold a launch or a supplier switch until documentation is current, not just a name on an org chart.
What doesn't need to change
The underlying discipline — material-level data over generic assurances, continuous rather than one-time verification, documentation built during development rather than reconstructed on demand — is identical at ten SKUs and at ten thousand. Scale doesn't change what good compliance looks like. It changes what breaks when you try to run it manually.