Product compliance

Nobody owns this, because everybody owns a piece of it

We reviewed the fifty largest UK high street fashion brands to establish who inside them is responsible for product compliance. In most cases the answer was not one person or one function. It was three or four, none of whom held the whole of it.

That is not an absence of commitment. It is a structural feature of how fashion businesses are built, and it explains why brands doing genuine work still cannot produce what the regulation asks for.

Book a 30-minute call →

The finding

Distributed, not absent

The assumption behind most of the incoming regulation is that a business has a product compliance function. ESPR, producer responsibility, due diligence and green claims rules are all drafted as though somebody holds the file.

In the businesses we looked at, the work was already being done. It was simply not being done in one place, or by anyone who would describe it as their job. Fibre data sat with technical. Facility records sat with sourcing. Filings sat with legal. Claims sat with marketing.

Each function was competent at its own part. None had visibility of the others, and none had a mandate to assemble them.

The consequence is specific. A brand can be doing more than the regulation requires and still be unable to evidence any of it, because evidence is a property of the assembled record rather than of any individual piece of it.

Where the data already is

You already hold most of it

Almost every field a product record requires is already generated by somebody inside the business as part of their normal work. It has never been asked for in a structured form, and nobody has told them it is now a legal record rather than an internal note.

Product and technical

Fibre composition and blend percentages, construction, care and wash, chemical test reports, trims and components, durability and repair information. Held on the tech pack, the specification and the QA file.

Sourcing and supply chain

Facility identity and location, country of origin, tier mapping beyond the first supplier, audit and certification status, onboarding records. Held in the vendor master and the supplier pack.

Compliance, legal and finance

Producer responsibility registrations and returns, customs entries and classification, the responsible economic operator position, claim substantiation and retained documentation.

The gap

What nobody owns is the assembly

What no function owns is the joining of it. One record per product, holding all three, reproducible on request, and accurate at the moment somebody asks.

That is not a larger version of any of the three existing jobs. It is a fourth job, and it is the one the regulation actually creates.

It is also why buying a passport platform does not resolve it. A platform is a place to put an assembled record. It does not do the assembling, and it cannot compel three functions to hand over what they hold in a form that fits together.

By function

What actually changes, and for whom

Buying and merchandising

The range you commit to now is the range that carries the obligation later. Vendor selection stops being a question of price, lead time and reliability alone, and becomes a question of whether that supplier can evidence what you will have to publish. A supplier who cannot is a markdown risk before it is a compliance risk.

Sourcing and supply chain

The request moves past tier one. Facility identity, processing location and chemical inputs sit two to four tiers upstream, at sites you hold no contract with. Getting them is a commercial negotiation conducted on the critical path, which means it belongs in onboarding rather than in an annual questionnaire.

Product and technical development

The tech pack becomes a compliance document. Fields that were internal reference become published, checkable statements, and a blend percentage that was approximately right becomes a representation somebody can test.

Import and logistics

Product data and customs data stop being separate systems. Country of origin, classification and the product record have to agree with one another, and they are currently maintained by different people to different standards.

Timing

The buying calendar, not the regulatory one

The dates that get quoted are the Commission's. A textile delegated act indicatively scheduled for 2027, with requirements applying around eighteen months after that. Read that way, there is time.

Read against a buying calendar there is considerably less. Product placed on the market when the requirements apply is product being committed to now. The supplier is being onboarded now, the tech pack template is being set now, and the vendor terms that would let you ask for tier two data are being agreed now.

Changing a range takes a season. Changing a supplier base takes longer. Changing how a business captures data takes longer still, and none of it can be done retrospectively for product that has already shipped.

Two obligations are not future dates at all. The ban on destroying unsold clothing and footwear has applied to large companies since 19 July 2026, and the Empowering Consumers directive applies from 27 September.

Where to start

Find out where the pieces are

The first piece of work is not a programme. It is a map: which obligations apply to your products and markets, which function already holds each piece of the evidence, where the gaps are, and who would have to be asked for what.

Most businesses have never had that written down, and it usually surprises them how much of it already exists.

How we run this as a function →

What this looks like for a brand →

Book a 30-minute call →