Overview

A supplier falsely claims to be an OEM factory for a famous brand (Apple, Sony, Volkswagen, etc.), or hands you another company's CE, FDA, ISO, or RoHS certificates as if they were its own — to win your trust and a higher price.

How It Works

  1. Fake brand authorization — "we manufacture for [big brand]" implies capability and quality. In reality, they either never worked with the brand or only processed a single non-core part once.
  2. Passing off certificates — they Photoshop their name onto someone else's certificate, or show a real certificate whose company name doesn't match the business license.
  3. Forged test reports — a professional-looking third-party test report that is actually self-made.
  4. Expired / out-of-scope certificates — the certificate is expired, or covers a product model completely different from what you're buying.

Why It's Harmful

  • Trust is abused — you relax your other due diligence because you believe the "big-brand certification."
  • Compliance risk — goods are seized, recalled, or fined at the destination when the certification turns out invalid.
  • Legal risk — using an unauthorized brand certification can amount to misrepresentation or even infringement.

Red Flags

  • The certificate's company name doesn't match the business license.
  • The certificate lacks a number, issuing body, or validity period, or the number can't be found on the issuer's website.
  • The certified product model / standard doesn't match your product.
  • They provide only a photo or screenshot of the certificate, not an online-verifiable original.
  • They won't give you the issuing body's verification link.

Solutions

1. Verify the certificate (mandatory)

  • CE — check the EU NANDO database to confirm the notified-body number (4 digits) is real and actually issued the certificate.
  • FDA — search the FDA establishment registration database (FURLS).
  • ISO — ask for the certification body (SGS, TÜV, DNV, etc.) and verify the certificate number on that body's website.
  • RoHS / REACH — require a third-party test report whose number you can verify with SGS/BV/Intertek.

2. Check "three-way consistency"

  • The certificate's company name = business-license name = contract party must match exactly.
  • The certificate's covered product model and standard must match exactly what you are buying.

3. Verify "big-brand OEM" claims

  • Ask for proof of the brand relationship (purchase orders, NDAs, authorization letters).
  • Note: a legitimate OEM usually has a confidentiality obligation and may not be able to show anything. If they eagerly produce an "authorization letter," be suspicious — it may be forged.
  • Indirect check: see whether the factory appears on the brand's public supplier disclosure list (some brands like Apple publish one).

4. Test independently

  • For critical products, draw your own samples and send them to a third-party lab (SGS, BV, TÜV, Intertek) for independent testing.

5. Contract terms

  • Add: "Party B warrants that all certifications provided are genuine and valid; Party B bears full liability for any loss caused by certification problems."

Tools & Resources

  • EU NANDO (notified bodies): https://webgate.ec.europa.eu/nando
  • FDA establishment registration: https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfRL/rl.cfm
  • Certification body websites: SGS, TÜV, BV, Intertek, DNV

Key Takeaway

A certificate's value lies in being verifiable online, not in looking impressive. Any certificate you can't verify on the issuing body's website is invalid. And always remember: certificate name, business license, and contract party must match exactly.