Ask for supplier documents only after defining the decision each item must support. Build one controlled register for the exact legal entity, site, tea, intended use and destination. State each file's purpose, scope, issuer, date requirement, reviewer, decision rule and update trigger. A folder of certificates is not an approval record unless its evidence is current, relevant and consistent.

Define the approval unit before requesting files

“Approve the supplier” is too broad. A trader may sell tea made at several factories; one factory may make several grades or flavoured products; and different hazards may be controlled by the grower, processor, packer, laboratory or importer. Freeze the approval unit as legal supplier + manufacturing/packing site + tea or product family + intended use + destination market. Then identify which entity controls each relevant hazard, claim and traceability step.

Different records answer different questions: registration supports legal identity, an audit supports a system decision, and a lot COA supports only its stated tests and sample. Link each file to one question instead of treating one impressive document as universal proof.

Use a ten-block request register

Evidence blockRequest with scopeAcceptance checkUpdate trigger
1. Legal identityCurrent registered name, address, business identifier and authorised contactNames and addresses reconcile across contracts, invoices and official recordsLegal-name, ownership or address change
2. Site and roleManufacturing, blending, packing and storage site list; activity performed at eachThe actual producer and hazard-controlling entity are not hidden behind the sellerSite, subcontractor or process transfer
3. Product definitionTea type, ingredients, grade/style, origin wording, intended use and destinationMatches the controlled bulk tea purchase specificationFormula, source, claim, use or market change
4. Process and hazardsProcess-flow summary and evidence relevant to who controls identified hazardsScope fits the actual product and does not rely on generic “low-risk tea” wordingNew hazard information, equipment or process change
5. Licences and certificationsOnly licences legally relevant to the activity and voluntary certificates the buyer actually usesIssuer, holder, site, activity, product scope, status and dates are verifiedExpiry, suspension, scope or authority change
6. Verification evidenceRelevant audit results, test history, inspection records and corrective-action statusMethod, auditor/laboratory, scope, findings and closure can be assessedFailure, complaint, overdue action or scheduled review
7. Lot controlsLot-code logic, traceability flow, sampling responsibility and example record setInputs, production, packing, tests and shipment can be joined without assumptionsCode, software, warehouse or record-format change
8. Packaging and labelsFood-contact declaration/evidence, pack specification, marks and controlled artwork inputsMaterial, intended conditions of use, product identity and market matchMaterial, converter, pack or artwork revision
9. Performance historyRelevant complaints, rejections, recalls, regulatory actions and completed correctionsPeriod, product/site scope and unresolved issues are clearNew event or adverse trend
10. Change commitmentNamed changes requiring notice, notice period, evidence due and buyer responseContract language supports hold, reassessment and reapprovalEvery material change or contract renewal

The register is a buyer-designed control, not a universal legal checklist. Adapt it to the tea, supplier role, destination, processing and relevant hazards or claims.

Collect the pack in three decision gates

Gate 1: pre-screen identity and fit

Before exchanging confidential files, confirm the legal counterparty, actual manufacturing site, product family, use, destination and core specification fit. Use the Chinese tea factory verification method for identity and facility checks. Stop if the seller will not identify who manufactures or packs the tea.

Gate 2: approval evidence

Request the risk-relevant process, hazard-control, compliance-history, audit, testing, traceability and packaging evidence. For a covered U.S. importer, 21 CFR 1.505 requires an evaluation of the food hazard analysis, the controlling entity, supplier procedures and practices, applicable compliance information, food-safety history and other necessary factors. That is a legal FSVP duty for the importer in scope, not a document list that automatically applies worldwide. The site's U.S. FSVP release checklist explains that market-specific decision.

Gate 3: first-lot and routine evidence

After source approval, request only the records needed for the lot: final specification, lot identity, sampling record, agreed tests, packing/marking check, quantity reconciliation and shipment documents. Connect them through the lot-control and traceability method. Maintain corporate-document expiry and change triggers separately.

Review every file with six checks

  1. Source: obtain the file through a controlled channel and verify the issuer or official register where risk warrants. A logo or scan alone is not authentication.
  2. Scope: confirm the holder, site, activity, product, process, method and market actually covered. An audit of a warehouse does not cover a separate tea factory.
  3. Time: record issue, audit, sample, test, expiry and review dates. “Valid” does not mean recent enough for the buyer's decision.
  4. Linkage: connect the evidence to the approved unit or lot using names, addresses, product identifiers, lot codes, sample seals and report numbers.
  5. Consistency: compare facts across the pack. A factory name, ingredient statement, manufacturing role or pack material that changes between files is a question to resolve, not a clerical detail to ignore.
  6. Decision: record who reviewed the evidence, against which requirement, with what result and follow-up. Supplier submission and buyer approval are separate events.

For technical reports, use the COA evidence-boundary checklist. Retain version history and show which approval or lots depended on each version.

Classify gaps instead of chasing “complete paperwork”

StatusMeaningBuyer action
AcceptedAuthentic enough for the risk, in scope, current and consistentRecord the supported decision and next review trigger
ClarifyAdministrative ambiguity could be resolved without changing the controlAsk a precise question; keep approval or lot status defined
Alternative evidenceThe requested format is unavailable but another record may answer the same questionAssess equivalence; never waive the underlying requirement by convenience
Expired or staleThe evidence no longer covers the required period or buyer maximum ageRenew, intensify another control or hold the affected decision
Contradictory or out of scopeIdentity, site, product, process or result conflicts with the approved basisStop and investigate before approval or release

A missing voluntary certificate may be irrelevant. A missing legally required licence, unresolved site identity or hazard-control gap is not. Define consequences before requesting the file.

Keep requirement types separate

  • Legal requirement: applies to operators and products in its jurisdiction. EU Regulation 178/2002, for example, requires food businesses in scope to identify suppliers and business customers and make traceability information available to authorities; it does not prescribe this entire ten-block pack.
  • Official guidance: FDA's final FSVP guidance explains the agency's current thinking and is nonbinding unless it cites a legal requirement.
  • Voluntary standard: Codex CXC 1-1969 recommends procuring incoming materials to specifications, verifying them where necessary and keeping key supplier, receipt and quantity information. Codex guidance is not automatically a buyer's domestic law.
  • Trade reference: a private audit scheme, grade code or common questionnaire can structure communication but must be checked for scope.
  • Buyer specification: converts intended use and market needs into measurable product and evidence requirements.
  • Contract requirement: makes document delivery, confidentiality, change notice, access, review timing, holds and remedies enforceable between the parties.

Common buyer mistakes

  • Sending one universal questionnaire before defining the tea, site, use or market.
  • Approving a trading company without identifying the actual manufacturer and packer.
  • Requesting every certificate available instead of the evidence needed for a decision.
  • Treating a third-party audit as legal approval or lot release.
  • Accepting a certificate whose site, product or activity scope does not match.
  • Ignoring conflicting names, addresses, ingredients, manufacturing roles or dates.
  • Keeping current files but no review decision, version history or affected-product link.
  • Using expiry dates alone and missing event-driven changes or adverse information.
  • Demanding confidential records without defining redaction, secure access or reviewer need.
  • Letting missing paperwork drift past purchase, booking or lot-release deadlines.

Practical conclusion

A usable supplier pack follows the sequence approval unit - decision question - scoped request - source check - scope/time/link review - contradiction check - documented decision - expiry/change trigger. Keep the register beside the supplier approval record, not as an uncontrolled email attachment list. Feed material changes into the supplier change-control plan and schedule ongoing evidence using the risk-based verification-frequency method. For a proposed purchase, review Yunjing Tea's sample-to-shipment quality controls and send the tea, destination, intended use and decision-based document list before setting approval deadlines.

Sources checked 18 September 2026: 21 CFR 1.505 and 21 CFR 1.506, with eCFR Title 21 displayed as current through 16 September 2026; FDA's January 2023 final, nonbinding FSVP guidance; Codex CXC 1-1969, General Principles of Food Hygiene, 2022 revision / 2023 edition; and the consolidated Regulation (EC) No 178/2002 dated 1 January 2026, especially Articles 17 and 18. Confirm the current destination law, supplier role, product risk and contract before applying a real request list.