Track supplier certificates
Some paperwork belongs to a batch. An NSF registration, a GMP certificate, a certificate of insurance or a third-party audit report doesn't — it belongs to the supplier, and it's true for a validity window rather than for a shipment.
That difference is why these are kept on the supplier rather than in the lot archive. They expire on their own clock, and the thing you need is a warning before one lapses, not a discovery afterwards.
Before you begin
- You need permission to update suppliers.
- Have the certificate files to hand, with their issue and expiry dates.
Set which certificates a supplier must hold
-
Open the supplier and go to the Compliance tab.
-
In Required certificates, pick the types this supplier has to keep current — for a contract manufacturer that's typically an NSF certificate, a GMP certificate and insurance.
-
Click Save.
This is what makes compliance measurable. A supplier with no required types isn't compliant or non-compliant — the question simply doesn't apply to them, and SKU.io shows no indicator at all rather than a misleading green tick.
Upload a certificate
-
On the same tab, click Upload certificate.
-
Choose the file and pick the Document type.
-
Fill in:
- Issuer — the certifying body or auditor, not the supplier themselves.
- Reference — the certificate number printed on the document.
- Issued and Expires — the validity window. The expiry date is the one that matters: it drives both the status and the reminders.
-
Click Upload.
The certificate appears in the list, sorted by soonest expiry, with a chip showing whether it's Valid, Expiring or Expired.
Reading the supplier's posture
A banner at the top of the tab states the position in one line: complete, or incomplete with the reason — which required certificates are missing and which have expired.
The same posture appears in two other places so you don't have to open the tab to find out:
- A Compliance current / Compliance incomplete chip on the supplier's header.
- A Compliance column on Contacts → Suppliers, so you can scan every supplier at once.
Both are blank for a supplier that requires nothing.
Renewal reminders
Once a certificate has an expiry date, SKU.io warns you at 90, 60, 30 and 15 days before it lapses, through the usual alerts. Each threshold fires once per certificate, so you get a sequence of warnings rather than the same one repeatedly.
Turn the alert on under Expiring Compliance Certificates in your alert settings to choose who receives it.
When the certificate is renewed, edit it and move the Expires date forward. That re-arms the reminders, so the new certificate warns again next year rather than staying silent because last year's warnings were already sent.
To replace the actual file, upload the renewed certificate as a new document rather than editing the old one. A renewal is a different document with its own validity window — keeping both preserves the history of what you held and when.
It never blocks a purchase order
When you open a purchase order for a supplier whose certificates are missing or expired, a banner names the gap and links here. It does not stop you raising, sending, or receiving the order.
That's deliberate. Blocking procurement on a paperwork gap is how a compliance feature gets switched off — a buyer who can't place an order under deadline will have it disabled by the end of the week. It informs the person who can fix it and gets out of the way.
Next steps
- Find a compliance document — the lot-level archive, which is separate from this
- File documents on a lot — batch paperwork, which belongs to the lot