Three questions into an audit, an EHS manager at a mid-size specialty chemicals manufacturer watches the tone in the room change. The auditor isn’t asking whether a substance is compliant. The auditor wants to know how the team reached their conclusion, who signed off on it and when the underlying regulation was last checked.
The manager has an answer, but not a trail.
This gap is becoming one of the most common failure points in manufacturing compliance today and it has nothing to do with access to information. If anything, teams have more regulatory data available to them than at any point in the industry’s history; public databases, AI-powered search tools, internal trackers, spreadsheets passed between departments. Finding an answer isn’t the bottleneck it used to be. Defending that answer is the harder problem and it’s the one keeping compliance leaders up at night.
Information isn’t the same as evidence
Regulatory frameworks such as PFAS restrictions, REACH, TSCA and GHS 7 don’t just change often; they change unevenly across jurisdictions, product categories and supplier tiers. A substance cleared under one framework six months ago may carry new restrictions today. Teams can usually find out that something changed. What’s even harder is proving, months later, that the decision made at the time was sound, properly sourced and reviewed by someone qualified to make the call.
This is the quiet shift happening across manufacturing compliance functions; the standard for a “good” answer has moved. It’s no longer enough to be right; teams need to show their work and they need to produce it quickly, without reconstructing it from memory or digging through old email threads when an auditor, customer or regulator asks.
Where the risk actually lives
Ask most compliance leaders where their biggest exposure sits and the answer is rarely “we don’t know the regulations.” More often, the exposure is quieter than that; a decision made by one person, on one system, without a record of the source material or the reasoning behind it. When that person leaves, changes roles, or simply can’t recall the details a year later, the company is left holding a conclusion it can no longer defend.
That risk compounds at multi-site manufacturers, where the same regulatory question can get answered three different ways by three different teams, while none of them aware another team already asked it.
Three questions worth asking
Here are a few questions compliance and EHS leaders can ask to surface how prepared their teams really are.
- Can we trace any regulatory answer we’ve given in the last year back to its original source in under a few minutes?
- Do we know who reviewed it and when it was last confirmed against current regulation?
- If an auditor asked us to defend a decision made six months ago, could we do it without pulling together a paper trail from scratch?
Most teams can answer the first question, are we compliant, with reasonable confidence. Far fewer can answer the three above with the same certainty and that gap is where audit findings, customer disputes and regulatory penalties tend to originate.
The direction the industry is heading
As manufacturers lean further into automation and AI-assisted tools to keep pace with regulatory volume, the ones getting it right share a common trait; they’re treating traceability and expert verification as core requirements, not features to bolt on later. The goal isn’t just faster answers. It’s answers that can survive scrutiny long after they are given.
The teams that build that discipline now will spend a lot less time reconstructing the past and a lot more time staying ahead of what’s coming next.