How to Require Subcontracting Disclosure From China Suppliers Before Production

A factory quotation can create a simple impression: one supplier, one production site, one set of controls. Actual manufacturing is often more distributed. A supplier may buy a molded part, send metalwork for surface treatment, use an outside laboratory, hire a packaging house, or place a capacity overflow order with another workshop. None of those arrangements is automatically a problem. The issue begins when the buyer does not know which product requirement, process step, material source, or delivery commitment depends on an outside party.

China supplier subcontracting disclosure is a controlled process for identifying outsourced components and manufacturing steps before the buyer releases production. It gives the buyer enough information to decide whether the outsourced activity is acceptable, which evidence is needed, what changes require notice, and who remains accountable if the product does not meet the approved specification. It is not a request for every trade secret in the supplier’s network.

This article provides general sourcing and quality-management guidance. The FDA and ICH materials cited use pharmaceutical examples and do not set the legal obligations of ordinary buyers or China suppliers. Product safety, regulations, labor, sanctions, country-of-origin, intellectual property, and contract rights can require specialist advice. Set disclosure and approval rules with your technical, quality, compliance, and legal advisers when those topics affect your product.

Keep the contracted supplier accountable

A buyer may contract with a factory that uses outside processes. That does not mean the buyer has contracted separately with every outside workshop. The contracted supplier should remain responsible for meeting the purchase order, drawings, approved materials, quality records, and shipping commitments unless the buyer has agreed otherwise in writing. A subcontractor is part of the supplier’s production route, not a reason to make accountability disappear.

The useful question is not “Does the supplier outsource anything?” Nearly every factory purchases some materials or services. The question is “Which outside activity can affect the product, requirement, delivery, traceability, or buyer commitment, and what control should apply?” A low-risk purchased standard screw may need an approved-source record. An outside molding, plating, printing, testing, or final assembly operation may need a more detailed disclosure and buyer approval before use.

FDA’s ICH Q10 guidance discusses control and review of outsourced activities and purchased materials in a pharmaceutical quality system. It describes assessing provider suitability, defining responsibilities and quality communications in a written agreement, monitoring performance, and monitoring incoming materials from approved sources.1 Those are general management concepts. A commercial buyer can adapt them to the product risk without pretending that every consumer product needs a pharmaceutical quality system.

Supplier arrangement Buyer concern Reasonable control example
Standard bought-in component Material identity, fit, authenticity, and lot traceability where needed. Approved-source or component record, incoming check, and change notice for the defined part.
Outsourced finishing process Appearance, corrosion resistance, dimensions, chemical restrictions, or cosmetic consistency. Process disclosure, approved sample or specification, process certificate or test evidence where required, and change approval.
Outside tooling or mold shop Tool ownership, revision control, capability, and location. Tool register, approved drawing, custody record, and notice before transfer or modification.
Contract packaging or labeling Artwork revision, barcode, quantity, dates, and product mix risk. Approved artwork, packing instruction, line-clearance evidence, and buyer approval for site or process change.
External testing laboratory Method suitability, report integrity, sample identity, and result traceability. Laboratory identity, method reference, sample chain of custody, and original report.
Overflow assembly or alternate factory Process consistency, capacity, quality controls, delivery risk, and intellectual property exposure. Buyer approval before use, production-site disclosure, first-article or pilot evidence, and defined inspection plan.

A contracted factory may reasonably limit access to confidential pricing, supplier negotiations, or unrelated clients. The buyer does not need those records to make every approval decision. Request the information that changes the buyer’s product or delivery risk: the activity, site or provider category, affected part or process, approved specification, qualification evidence, change history, traceability route, and responsible supplier contact.

Define subcontracting in the purchase order

Supplier questionnaires often fail because the word “subcontracting” is undefined. One factory may report only final assembly at an outside facility. Another may report every purchased component. A buyer should define the term for the specific order. State whether it covers manufacturing, assembly, processing, testing, packaging, labeling, storage, inspection, product rework, or other services that can affect the supplied product.

The definition should focus on activities that transform, verify, handle, or materially affect the goods. It should not force a supplier to report office services or unrelated purchases. If the buyer wants to control component sources as well as outsourced processing, use separate fields. That distinction prevents an approved component list from being mistaken for approval to move a process to an unknown facility.

Definition field Buyer instruction Why it prevents confusion
Covered activity Name the operations that need disclosure, such as molding, coating, assembly, labeling, testing, or packing. The factory knows the request is about product-affecting work.
Affected product State the part number, product family, revision, and purchase order. Disclosure can be tied to the exact goods being approved.
Material source Identify whether a change to a critical component source requires separate disclosure. Bought-in materials and outsourced processing are not merged into one vague category.
Location rule State when the buyer needs the operating site, city, provider name, or provider category. The information request can match risk and confidentiality needs.
Prior approval rule Identify activities that require written buyer approval before use. Prevents the supplier from treating notification after production as sufficient.
Change trigger List site, provider, process, material, equipment, method, and specification changes that require notice. Gives the supplier an operational list rather than a broad promise to disclose changes.
Evidence level State the documents, sample, inspection, audit, or test evidence appropriate to the activity. Factories do not have to guess which evidence will support approval.

A clear definition also improves supplier selection. A factory that readily maps its production route may be a better match for a buyer who needs traceability. A supplier that refuses to identify even the activity and control path for a critical outsourced step creates uncertainty that should be considered before a purchase order is released. The buyer does not need to accuse the factory of misconduct. It can simply state that the requested transparency is part of the supplier qualification and production-release process.

Map the product and process before approval

Ask the supplier for a simple process map and component map for the product being sourced. Start with raw or purchased inputs and follow the product through fabrication, treatment, assembly, inspection, packing, storage, and shipment. Mark each step as performed at the contracted supplier’s site, performed by an outside provider, or not applicable. Identify critical components separately when their source affects fit, function, regulatory documentation, safety, performance, or customer expectation.

The map does not need an elaborate manufacturing manual. A one-page flowchart and a short register may be enough for a straightforward product. A more complex item may need separate maps for electronics, mechanical parts, packaging, testing, and finishing. The buyer should scale the request to the product. A map that is too broad produces generic boxes. A map that is too narrow misses the process that actually controls the defect risk.

Process-map question What the supplier should show Buyer follow-up
Where is the part made or transformed? In-house, outside provider, or purchased finished component. Check whether the response matches the quotation, sample, and factory capability discussion.
What requirement does the step affect? Dimension, performance, finish, material, label, packaging, or test result. Decide whether the step needs pre-approval, evidence, or routine monitoring.
Which document controls the step? Drawing, work instruction, material specification, test method, or artwork. Confirm the supplier has the current revision.
How is output checked? Incoming check, in-process check, final test, certificate, or sample review. Ask whether the check can detect the buyer’s critical failure mode.
How is the output identified? Part number, lot, date, provider code, batch, or process record. Confirm traceability is sufficient for the risk and order size.
What changes can affect the step? Site, provider, tooling, material, method, equipment, or parameter. Add the relevant triggers to the supplier change-notice rule.

Use the sample phase to test the map. If a supplier says coating is in-house but sample documentation shows an outside process certificate, ask for an explanation before mass production. If an inspection report lists a different production address than the one in the supplier disclosure, investigate whether it is an approved warehouse, related factory, or undisclosed subcontractor. An inconsistency does not settle the matter by itself, but it is a reason to pause and reconcile the record.

The product map should connect to the bill of materials, drawings, packaging instructions, and inspection plan. A factory may be allowed to buy standard packaging material from approved sources, but it may need buyer approval before outsourcing the final printed packaging process. The more accurately the map identifies the product’s control points, the easier it is to write rules that a supplier can follow.

Use a risk-based disclosure threshold

Do not demand the same evidence for every activity. The buyer should classify the outsourced activity by the impact of a failure and the ability to detect the failure before shipment. A process that changes a customer-facing logo, a regulated claim, an electrical safety component, a food-contact material, a tight-tolerance feature, or an item that cannot be inspected after assembly deserves closer control than a readily inspected standard carton.

Risk also depends on supplier history and change frequency. A factory with a long record of stable, documented output may need less frequent evidence for a routine outsourced operation than a new supplier using a new provider. An urgent capacity shortage may make overflow manufacturing commercially necessary, but it should not silently lower the approval standard. The buyer can allow a limited pilot with additional inspection while it gathers the evidence required for normal release.

Activity risk level Example condition Disclosure and approval approach
Routine Readily inspected standard packaging component with no performance or compliance claim. Register the activity or approved source; notify buyer of material change when the product specification requires it.
Controlled Outsourced printing, simple machining, or component assembly with visible or measurable requirements. Disclose provider category or site as agreed, controlling specification, inspection record, and notice before change.
High impact Coating, molding, electronics assembly, final assembly, functional testing, or a component that affects performance. Obtain buyer approval before use, provide qualification or sample evidence, preserve traceability, and define change-control triggers.
Restricted Safety-sensitive, regulated, customer-mandated, proprietary, or contractually named operation. Do not outsource or change source without explicit written authorization and product-specific technical or compliance review.

This framework does not decide compliance for the buyer. It helps the buyer decide how much transparency to request before it commits to production. For products subject to legal or technical controls, obtain qualified guidance before assigning an activity to the routine category. A factory may also have a legitimate reason to use an outside provider that has specialized equipment. The buyer’s interest is in making that decision visible and controlled.

Request a subcontracting disclosure register

A disclosure register turns the process map into an operational record. Keep it tied to a product, revision, and effective date. The supplier should update the register before it uses a new outside provider or moves an approved activity, not after an inspection finds a difference. The register can be a table in the quality attachment, supplier portal, or controlled spreadsheet, as long as changes are traceable.

FDA’s quality-agreement guidance for drug contract manufacturing discusses clearly defining the material or service, quality specifications, communication mechanisms, subcontracting considerations, change management, and the responsible party’s activities.2 The regulated setting is different from general China sourcing, but the record design is useful: describe the activity and what controls it, name the roles, and make the communication route explicit.

Register field What to record Buyer use
Product and revision Part number, SKU, drawing or artwork revision, and effective date. Prevents approval from being reused for a changed product without review.
Outsourced activity Specific operation, such as anodizing, PCB assembly, final pack, or laboratory test. Shows what the outside party actually does.
Affected requirement Finish, dimension, material, performance, label, packing, or test method. Connects the activity to the buyer’s risk assessment.
Provider identification level Provider name, site, city, approved-source code, or category as agreed. Balances commercial confidentiality with decision-ready information.
Supplier control Incoming inspection, process certificate, sample approval, audit, test, or lot record. Shows how the contracted supplier monitors the outside activity.
Approval status Proposed, approved, limited pilot, rejected, or expired. Stops an unreviewed provider from appearing in routine production.
Change notice requirement Event that requires buyer notice or approval. Makes the rule usable when a provider, site, process, or material changes.
Traceability record Lot code, provider batch, process certificate, packing record, or order link. Supports investigation if a later defect appears.
Responsible supplier owner Role and contact responsible for accuracy. Gives the buyer a person who can answer questions and update the record.

If the factory identifies an outside provider that it does not want to name, the buyer can decide whether a provider category, city, certificate, inspection evidence, or audit by an approved independent party meets the risk. Do not automatically accept a vague label such as “partner factory” for a high-impact process. Ask what the partner does, how the contracted factory controls it, and what evidence proves the output meets the buyer’s requirements.

Set approval and change-notice rules that work

Approval rules need a clear starting point. For high-impact activities, the supplier should not use a new provider, new production site, new process route, or new material source without written buyer approval. For controlled activities, the supplier may need to notify the buyer in advance and provide defined evidence. For routine activities, the supplier may update a register and retain the records for buyer review. Write the rule by product and activity, not as a vague request to “tell us about changes.”

A good change notice states the current approved condition, proposed condition, reason for change, affected product and orders, planned effective date, risk assessment or impact statement, supporting evidence, temporary containment if needed, and requested buyer decision. The buyer should respond with approve, approve with conditions, request more evidence, reject, or escalate. Silence should not become approval unless the commercial agreement expressly defines that outcome and a qualified person has reviewed the risk.

Change event Supplier action before use Buyer decision input
New outside production provider Submit register entry and required qualification evidence. Product risk, provider capability, sample or pilot evidence, and supplier control method.
Process moved to another site Notify buyer and identify affected process, equipment, and personnel changes. Whether a first-article review, audit, extra inspection, or new approval is needed.
Component-source substitution Submit proposed part, specification comparison, and test or sample evidence. Fit, performance, compliance, documentation, and traceability impact.
Tool transfer or major tool modification Provide tool ID, custody route, revision, and validation plan. Ownership, product revision, capability, and approval evidence.
New testing laboratory or method Identify laboratory, method, sample handling, and report format. Method suitability, result comparability, and chain of custody.
Capacity overflow or urgent production move Request limited approval before production, with extra controls. Delivery need, risk, inspection plan, and expiry of the temporary authorization.

Do not bury the rule in the fine print of a purchase order that factory production personnel never see. Send an operating summary with the quality attachment, train the commercial and quality contacts, and require an acknowledgment that names the responsible role. The supplier may have multiple internal departments that handle purchasing, engineering, production, and shipping. A buyer needs the rule to reach the person who decides whether to use an outside process.

Protect confidentiality while retaining useful evidence

A supplier disclosure request should be proportionate. Asking for all supplier prices, personal data, unrelated customer names, or a complete vendor list is unlikely to improve the buyer’s product control. It may also make the factory less willing to provide the records that matter. Define the minimum information needed for each risk class and specify who may access it.

For a high-impact process, the buyer may need the operating site, process description, controlling specification, quality evidence, and traceability record. For a routine purchased item, an approved-source identifier and incoming check may be enough. If intellectual property or customer confidentiality is involved, the parties can use a nondisclosure agreement, limited portal access, redacted reports, or an independent inspection arrangement. Those tools should not become a way to hide a provider change that affects the approved product.

Avoid requesting personal information about subcontractor staff. Request organization-level roles, records, and sites only to the extent needed for the commercial control. If a buyer needs to verify social, labor, or environmental claims, establish a separate program with qualified auditors and legal guidance rather than relying on a product subcontracting register.

Confidentiality concern Proportionate control Information the buyer can still request
Supplier does not want to reveal commercial pricing Keep price terms outside the disclosure register. Activity, product impact, quality control, approval status, and change notice.
Provider identity is commercially sensitive Use a provider code or limited disclosure if risk permits. Location or category, control evidence, traceability, and responsible factory owner.
Customer proprietary design Limit access to product drawings and evidence files. Confirmation that the outside provider uses the current controlled revision.
Test report contains sensitive data Share a redacted report or original result through a secure channel. Method, sample identity, result, date, and laboratory or provider authority.
Buyer wants an audit Use a defined scope and confidentiality terms. Evidence focused on the relevant product process and control points.

The buyer should retain an internal record of who approved access to information and which documents support the approval. This protects both parties when a product or provider changes later. It also prevents a new buyer employee from asking the factory to disclose sensitive material that the original agreement never required.

Verify actual use when the risk justifies it

A disclosure is an assertion. The buyer may need to verify it for high-impact products or when a supplier’s records conflict. Verification can be scaled. It may involve checking a process certificate against a production lot, matching a component lot to an approved-source register, reviewing a test report, inspecting a sample, requesting photos of a controlled process, commissioning an independent factory visit, or examining shipping and production records. Use methods that answer the actual risk question.

The buyer should not treat a factory visit as proof of every supplier statement. A visit may show the equipment and process in use on one day. It may not establish which provider made every lot. Combine observation with controlled documents and traceability. A certificate may show that an outside process produced a batch, but it should be linked to the correct product and order. A sample may confirm performance, but it may not reveal a silent shift to a different provider later.

Verification option Best use Limitation to document
Document review Checks current specification, provider register, traceability, and quality records. Depends on record completeness and authenticity controls.
Sample or first-article review Confirms an output against the approved baseline. Does not prove long-run consistency or later provider use.
Lot certificate or test report Supports defined material or process requirements. Must be linked to the product, lot, method, and source.
Independent inspection Observes selected conditions or checks a defined lot. Is limited to the agreed scope, location, and time.
Process or supplier audit Reviews controls for a critical outsourced activity. Requires appropriate access, scope, competence, and follow-up.
Incoming or pre-shipment inspection Checks product conformance at a defined point. May not detect hidden-source changes or latent process effects.

FDA’s contract-manufacturing guidance cites recommendations that agreements consider subcontracting, change management, and audit access in the drug-manufacturing setting.2 For a general buyer, that supports a basic principle: if the source matters to a product decision, agree on how it can be verified before the purchase order is issued. Do not wait until a customer complaint requires information the contract never required the supplier to keep.

Respond to unapproved subcontracting with a controlled decision

If a buyer discovers that a supplier used an unapproved provider or process, start by preserving facts. Identify the affected products, orders, lots, process dates, provider or site if known, current inventory, shipped quantities, and evidence available. Contain product where appropriate while the responsible technical and commercial owners decide whether the goods can be inspected, tested, accepted under a documented deviation, reworked, returned, or escalated.

Do not assume that an undisclosed outsource event automatically means the product is defective. The product may meet the requirements. It does mean the supplier bypassed the agreed control path, so the buyer must assess the product and process evidence before release or closeout. Repeated unapproved changes may call for stronger supplier monitoring, revised payment or release controls, a targeted audit, or a source change depending on the agreement and risk.

The corrective action should address the system gap as well as the immediate product. Ask why the supplier used the outside provider without notice. Was the approval rule unclear? Did an urgent capacity issue bypass a normal process? Did a purchasing team lack visibility into customer restrictions? Was a critical process not mapped? The answer should lead to a controlled update, such as a revised register, approval workflow, training, or additional review point.

Use this supplier request wording

The following language can be adapted for a sourcing or quality attachment. It is not legal advice and should be reviewed for your product and agreement.

Supplier shall disclose, before mass-production release, any outside party that performs a product-affecting manufacturing, processing, assembly, testing, packaging, labeling, storage, inspection, rework, or other activity identified in the buyer-approved subcontracting disclosure register for [product and revision]. Supplier shall remain responsible for all goods and services provided under the purchase order. Supplier shall not change an approved outsourced activity, provider, production site, critical component source, process, equipment, method, or specification without the notice or written buyer approval stated in the register. Each disclosure shall identify the affected product, activity, controlling specification, supplier control method, traceability record, effective date, and responsible supplier owner. Supplier shall notify buyer promptly if an unapproved activity is used or a proposed change cannot follow the agreed procedure.

Add your specific approval fields, evidence rules, and remedy provisions separately. The buyer should make sure that the factory can use the form before production begins. A long clause is not an operational control unless the responsible supplier contact understands it and has access to the current register.

Common mistakes in subcontracting disclosure

The first mistake is asking only, “Do you outsource?” The second is treating a purchased standard component as identical to an outside process that changes a critical feature. The third is approving a provider with no link to the current product revision. The fourth is requiring a change notice but not stating which changes need approval. The fifth is demanding confidential information that has no bearing on the buyer’s product risk.

Another mistake is assuming a supplier’s factory address proves the whole product is made there. The address may be valid for the supplier’s own operation while other controlled steps happen elsewhere. Use a process map, a disclosure register, and traceability evidence to understand the route that affects your product. That is more useful than trying to turn a supplier questionnaire into a background investigation of every company in its network.

FAQ

Is subcontracting always a problem when sourcing from China?

No. Many suppliers use specialized providers for materials, finishing, tooling, packaging, testing, or capacity support. The buyer should decide which outside activities need disclosure and approval based on product risk, contractual requirements, and the ability to verify output.

Should I require the name of every subcontractor?

Not necessarily. For routine low-risk activities, an approved-source code or provider category may be enough. For high-impact processes, the buyer may need the site or provider identity and evidence of control. Define the information level before the supplier quotes or starts production.

What changes should trigger buyer approval?

Typical triggers include a new production site, outside provider, critical component source, process route, major tool change, test method, material, or specification. The final list should match the product and agreement. State the triggers in the disclosure register rather than leaving them to interpretation.

Can a supplier use an outside factory during a capacity shortage?

Only under the approval route stated in the agreement. A buyer may allow a limited pilot with extra inspection, sample approval, or traceability evidence. The factory should disclose the reason, site, scope, controls, and effective date before the substitute source is used.

How can I verify an outsourced process without visiting every provider?

Use a proportionate combination of product records, traceability, certificates or test reports, sample checks, independent inspection, and targeted audits. Select the method that can address the product risk. A single photo or generic certificate is rarely enough for a high-impact process.

Make the production route visible before it changes

China supplier subcontracting disclosure works when the buyer maps the product route, identifies high-impact outside activities, requests only decision-ready information, approves changes before use, and keeps the contracted supplier accountable for output. This control helps the buyer discuss capacity and specialized processes openly instead of discovering a material route change after production begins.

Supplier Ally can help buyers create a subcontracting disclosure register, review factory process maps, coordinate sample or inspection evidence for controlled outside processes, and maintain change records before production release. The aim is a clear, proportionate control system that supports supplier flexibility while protecting the approved product.

References

[1] U.S. Food and Drug Administration, “Q10 Pharmaceutical Quality System”

[2] U.S. Food and Drug Administration, “Contract Manufacturing Arrangements for Drugs: Quality Agreements”

Leave a Comment

Your email address will not be published. Required fields are marked *

en_USEN
Scroll to Top